Regular apps can't typically access the MAC address of the connected device. Additionally, with BLE (& Bluetooth 5?) the MAC address is required to rotate regularly as part of the spec (IIRC even while connected but certainly the broadcast address).
But you are correct that regular apps can't address the MAC address of connected Bluetooth devices, so the tracking vulnerability that OP is suggesting isn't really possible.