Sure, for each part there is usually some exploit known, but the whole thing is getting much much harder to the point where if the average user said "How do I screenshot this app" the only real answer is to take a photo of the screen.
The PPV in the 90s was broken because too few bits were used on the encryption and it became possible to essentially brute force the keys, IIRC.
If Android really cared about its users, all it would have to do is permit user-prompted screenshots and screen recordings but still block other app access. I can't think of a time where I'd want my own phone preventing me from screenshotting, but I can see the use case for general screen access prevention.
I don't personally know a root-obly way to disable this, but xposed has the disable_flag_secure module that I'm weary of using because it removes the flag everywhere.