I thought Apple was checking apps? How did this go through? In any sane jurisdiction exposing PII like that is illegal.
Better to make secure operating systems that inform users of bad access patterns and let the developers be free to produce.
Nothing protects you from giving info to a broken backend though, so people should be more cautious and repercussions for insecure backends should be higher.
Apps on the app store are hardly much better than anywhere else.
iOS users still spend more dollars per average in apps than android ones even if android has more users i think ?