Those are memory corruption bugs which are potentially exploitable vulnerabilities. There are no false positives for the security protections in hardened_malloc including the hardware memory tagging (MTE) integration. It only detects invalid memory corruptions via use-after-free or out-of-bounds accesses. Due to a relatively high number of apps having invalid memory accesses during regular use, we don't enable MTE for all user installed apps yet. We always use MTE for the kernel and userspace code in the base OS but it's opt-in for most user installed apps via a global toggle to enable it by default and a per-app toggle mainly intended for opting out for incompatible apps.
OsmAnd has a massive amount of legacy C++ code which hasn't been heavily tested with HWASan and MTE. It has a history of having many memory corruption bugs discovered and reported by GrapheneOS users. That's the exploit protections in GrapheneOS working as intended and it's why there are per-app compatibility toggles to work around apps which can't be used due to memory corruption during regular use. It would be better if apps had higher quality native code and didn't need us to provide compatibility toggles but that's the way things are. It's much worse on desktop operating systems.