A fake or scam app can gain access to your phone, but it will never know your passphrase.
Which of course should only be stored in your brain and not on any devices.
Are you suggesting that people should delete and re-input their seed phrase every time they want to manage their crypto? That sounds like a huge inconvenience for most people.
Anyway, not surprised to see some fake apps managed to bypass the filter of an official marketplace. I remember reading somewhere that a scammer can submit a barebones app to get approval and modify it later to include malicious code. There are even cases where a developer got hijacked and they uploaded a fake app from their official store account.