Many apps I use daily require internal storage permissions and a bunch of them drop random dotfiles with magical IDs in there. Xiaomi even dumps a world readable unique device ID on the emulated SD card. Not all apps require external storage permissions, but even then there's tons of APIs that can be used to fingerprint the device.
Google is trying their absolute hardest to reduce the fingerprinting surface but as long as system APIs that work with user content like these exist, there will always be something to fingerprint users by. If everything else fails, you could just embed a webview that uses all the javascript stalking we've grown so accustomed to.
It's sad but I don't think you can prevent native code from fingerprinting your device. The sandbox just isn't tight enough and users are too willing to give out permissions.
I can see Google using a predefined set of colours in some update instead of the raw colour values to combat this, but that's only one of many ways apps abuse their users' devices. Unless app stores kick out apps that fingerprint devices, I don't think we'll see any non-fingerprinted devices any time soon.