On Android, an updated app is validated by the system to be signed by the same signing key hash as was used previously.
The most recent (v3, IIRC) apk signing scheme allows you to update an APK and sign it with the old key, and committing a future new signing key, which permits re-keying an app.
To use this, I believe you need to ship a platform (operating system) update, as the underlying apps are signed using old APK signing schemes.
These OEMs are likely not always shipping the latest OS version, but could look to techniques used in the custom firmware world, where there are tools to allow reflashing the OS without losing app data when changing system signing key.
It requires engineering effort for already released devices though, so I suspect we will see very little action - as usual, the eyes are on the future products, not on previously released products.
I assume Google play protect will be used to carefully patrol and detect apps on devices signed by the leaked keys, but this isn't hugely helpful for anyone concerned about "zeroday" style targeted attacks against them.