It could be used as part of the process, for example to access a URL with an android exploit on it that the user would not normally visit. It could also detect periods of inactivity, or high background noise. This is a real attack vector not worth dismissing.