The problem is the env stays readily accessible to most programs with similar permissions and all child programs if no special actions are taken.
This is (part of) the reason programs accept secrets like passwords normally only (or strongly recommended) over stdin or similar instead of env variable or cmdline.
Or why it's not rare (or was in the past, probably is today) to have a encrypted cert file and inject the password to it through a side channel.
It's also not rare for programs to dump environment variables in various situations, including to logs. Or e.g. an intrusion detection program might snapshot all programs running + their cmd arguments + their (creation) env and then run analysis on it.
And while you can use e.g. selinux and similar to add a ton of security and prevent such issues, or use systemd to run the program under ad-hoc users with minimal permissions and various isolation it's very often not done.
EDIT:
To be clear I'm not saying you can't use secrets in environment variables safely.
I'm saying by default by their design environment variables are not "secure for secret passing". But many things for which stuff like that is true can, under the right circumstances, still be used securely.