My elderly mum has an Android phone. She is not very tech-literate.
She might see a full page ad "your phone has a virus, clean it now", or somehow end up on something like it (e.g. a scam email).
She then dutifully clicks on it, which prompts to download an apk. The webpage provides clear instructions for how to install the just-downloaded APK.
That APK (app) then walks her though enabling ADB, so it can "clean the phone". The app gave very good instructions (customized to reflect the UI that her device manufacturer would use), so she manages to click through to the hidden settings menu and enable ADB.
The app can now exfiltrate all sorts of data, without needing any scary permissions prompt which will tell the user what is being accessed.
I think this sort of pattern is very real, and many users are being affected by these scams. And undoubtedly more android users than iOS ones.
Finding a balance that allows power users like me to use my device as I wish, and protecting regular users, is quite hard. I think the solution Google came up with of requiring a 24 hour wait, + some extra scary warnings, for unsigned apps is a step in the right direction, it helps less tech literate users avoid scams, and power users just have to be patient for 24h. But of course it's still not satisfactory for everyone, mum might still get scammed, and power users get annoyed at it.