They can pretty much pick and choose unless the data is encrypted --- and most of it is not.
https://www.xda-developers.com/android-permissions-bypass-pl...
https://www.xda-developers.com/android-permissions-bypass-pl...
As far as I know, most (if not all) of the concerns shared have been addressed in the following 2 years, so I would assume that this is not an issue anymore in 2023 - or at least not as severe. I believe that new loopholes exist, but this one seems outdated to me.
btw "The researchers discovered that the Shutterfly app was accessing the location tags of photos' EXIF metadata. All that's required is the READ_EXTERNAL_STORAGE permission" sounds ridiculous. If you grant permission to read entire files, of course the app can read metadata.