I actually know the team that does security vuln automation for Google Play. They've found millions of vulns in apps over the years. One of the challenges they face is precisely this sort of headline: how do you use static analysis to find vulns and ensure that you don't inundate users with false positives, forcing them down the admittedly limited support channels.
> The solution, I think, is obvious: Google needs a "zone defense" with the play store, a much larger (and expensive) staff, to do in-depth app reviews and be a stable, stateful relationship with the developer over time. This person would, in fact, become a 3rd party "expert" on a small set of apks and their contents, with a "feel" for what is changing over time, with the core mission of protecting users from malice, but working with devs, as a human being.
This sort of exists. Google pays external hackers who find vulns in popular apps via a rewards program. These don't need to be Google's apps. There may be other systems for top partners or specific kinds of apps (the org is big) but I'm not aware of anything personally.
Expanding beyond a small subset of apps is challenging. Not only are there millions of apps, each app contains tens, hundreds, or even thousands of individual apks. The staff needed to have a concierge for each app would be absolutely freaking enormous, perhaps even larger than the number of people on the planet who actually have deep security expertise on the Android platform.