This seems to me to be something that should have been issued as an OS-level patch.
Apple could prevent a lot of these issues by using an application-specific UDID generated by the device. Hash the UDID with a random salt generated from entropy on the device, and use it only for that app install. Developers then couldn't track you from install to install, or across their application ecosystems. Privacy issue averted.
Any existing calls that hundreds of thousands of applications make to currently get the UDID just return this application-specific one instead.