It's all just really dumb fearmongering that ultimately hurts the credibility of privacy advocates as a whole.
The sad thing is, these companies are collecting mass amounts of sensitive data and using it to drive ads, and we should be doing more about it. There's absolutely no reason to fabricate nonsense like this, the reality is already terrifying enough to creep people out.
Maybe a lot of the folks this happens to haven't denied microphone permission? Or maybe someone around them hasn't? Facebook has a calling feature, chances are people (or others around them) have given it access without realizing it. I have certainly caught Facebook Messenger snooping on my location when it had no business to, merely because I had granted the permission days ago when sharing my location with my friend, and forgotten to deny it again. It spooked me out and made me realize how they trick you into sharing info you didn't intend. I don't see why they wouldn't opportunistically exploit mic permissions just the same. Hell, that might be why they created the calling feature in the first place!
What if they only do it while the display is off? Are users likely to notice it after turning the phone back on?
What about EM field detectors? Voice vibrates things which shows up indirectly.
Modern phones have numerous sensors.
Edit: one interesting paper found after some searching:
If your phones and other devices were secretly listening to and recording every word you said to market to you, despite Apple, Google, Amazon and others explicitly saying they don't do this, not only would this be a scandal of epic proportions, every lawyer who could fog a mirror would be salivating at the billions in class action payouts that they would win.
That's why I hate this stupid conspiracy theory so much - it makes no sense in the real world even if you assume all the companies and people involved solely care about making more money.
1. As you point out, this isn't even some "super secret government" tracking you. They are basically advertising that anyone selling any random shit could take advantage of this feature. So obviously it would be trivially easy for anyone with the motivation to go and buy some of these ads to get clarity if some voices were actually being tracked. There is literally no way for this technology to be hidden given how it is described in TFA.
2. Companies don't need these secret tracking technologies, because the overt tracking ones already give them tons of information: your location, what you searched for, browsing history, your friends and family, etc. etc.
3. Given that ads are already super targeted, whenever this story comes up you always get these anecdotes of "I was talking about some totally random thing like pantyliners and then THE VERY NEXT AD I SAW WAS FOR pantyliners! Indisputable proof!" I've certainly had a similar experience. But it's certainly not that hard to see how these kinds of coincidences would be quite common given how good ad targeting already is.
Like the saying goes, "Anyone who is a conspiracy theorist has never been a project manager..."
They could be lying, but it’s not at all unreasonable to take their word for it when so many people report dramatic specific hits on their speech.
If the CIA put up a page on their web site saying that they really did sell crack in the 80s, would you still try to debunk that claim? (to pick a random example)
"These companies" in this context are shitty 3rd rate ad companies that have provided no proof of their capabilities. The reason it's fine to dismiss their claims as BS is that the companies that actually make the devices have explicitly said it's not possible, and if these device-making companies were lying it would be a scandal of gargantuan proportions.
This could also be a weasel answer. What they're saying is that apps are not allowed to do this via official permissions or channels in the OS. It's like YouTube saying there is no CSAM on YouTube. What they're saying is that they do not allow CSAM on YouTube and remove it when they find it, not that it can't possibly exist.
I posted this elsewhere as one possible method:
https://arxiv.org/abs/2212.01042
Phones have so many sensors with legitimate uses it might actually be hard to prevent an AI-enhanced sensor fusion approach from extracting this kind of information. Mitigations may require things like the injection of randomness into sensor feeds, which is also a mitigation used to prevent timing side channel attacks against hardware. But this is a lot harder to get right than it sounds. You have to make sure it's enough randomness to completely swamp the signal but not enough to destroy the usefulness of the system.
Then there are microphones in devices like smart TVs and other Wifi-enabled gadgets that have a well established history of shady behavior. It may not be your phone. It may be other devices in the room. But if your phone is there then your location can be matched to the data later in a data fusion pipeline.
As for these being crappy little companies: (1) if you listen to the pod or read some of the articles on this, some of them are larger companies like Cox Media Group and (2) crappy little companies are actually more likely to do shady fly by night shit.
I'd find it much more likely that some crappy little adware company would do something like this than Meta or Google, because the latter can be sued while the former will just evaporate if you try to sue it. But once the data is gathered it'd be sold to data brokers where it'd be fused with lots of other data and made available to larger companies to power their targeting algorithms. This is how the adtech industry operates. The shady stuff is done by disposable or offshore companies and then the data is laundered through the data broker market.
I don't know if acoustic eavesdropping is happening at any scale, but I am absolutely 100% sure that if it can be done it is being done by someone.