You're absouletly right. Here's a pretty good article covering some of the attacks that could be done against radio navigation systems:
https://arstechnica.com/information-technology/2019/05/the-r...
On a foggy day when the visibility is right at minimums, I can imagine a huge risk of aircraft being sent off-course right before landing. Hopefully the pilots would still be able to recover the situation - the TOGA button is right there on the thrust levers on most aircraft - but nobody is infallible.
I would imagine that some military transport aircraft have backup, INS-based navigation systems that create a synthetic glidepath without external radio signals. Airbus have been trying to introduce such systems on commercial airliners for quite a while, although that is intended to allow landing on more remote runways rather than specifically to improve security against malicious interference.
All that is to say that the lack of fatal aviation accidents that we know were caused by malicious radio interference doesn't in any way make the attack less feasible.
Digital signatures, even with conventional X509 certificates straight out of the OpenSSL library, would go a long way to mitigate this risk. What about the risk of the signatures failing? The worst-case scenario is that the pilots get a warning on their ECAM display: "Comms not secure". That should at least alert them to the possibility of false readings even if it can't correct them.