> Erm, why would you ever want an app for your bank on your mobile phone?
To easily check balances and make transfers wherever I am. This is possible without the app, but the app makes it easier/quicker than the mobile site in most cases.
> So that when you get mugged, it can turn into a kidnapping?
How do you suggest a mugger to find out whether such an app is even installed, let alone do anything about it, in this day and age of full-device encryption being the default? Even assuming a mugger somehow has access to the nation-state-level compute resources and exploit tools necessary to gain access to anything on my phone, by the time the mugger has finished using said tools and compute resources, I'll have already changed my passwords and invalidated existing login sessions.
Also, kidnapping involves considerably more effort and risk than mugging, so this is a weird argument in general. The vast majority of people with both smartphones and bank accounts almost certainly have banking apps installed on their phones, and I know of precisely zero cases of muggers deciding "oh you have a banking app? lemme go find my windowless van and kidnap you, drawing considerably more attention to me and giving you considerably more reason to violently defend yourself instead of cooperating; surely nothing will backfire from that, no siree!".
Muggers quite frankly don't give a flying fuck about the apps on your phone. They want your cash and/or whatever they can quickly fence.
> Segregating apps onto different devices is the way to go to protect yourself from corporate malware.
Having firmware that gives you fine-grained app permissions that you can freely grant/revoke also accomplishes this. If apps on the Play Store are subverting that, then banking apps are probably the least of your worries.