> In terms of the origins of the app, Google told me “this is not an Android platform nor Pixel vulnerability, this is an apk developed by Smith Micro for Verizon in-store demo devices and is no longer being used. Exploitation of this app on a user phone requires both physical access to the device and the user's password.”
If an attacker has your phone and your password, it's game over anyway, who cares if some random app could allow MITM connections over HTTP.