For example let's say you handed your phone to your kid, they downloaded a free app, gave that app your entire contact list, and then that app spammed everyone you know? For the sake of example let's call that app LinkedIn.
It’s bad that LinkedIn has such a reputation that I automatically assume they likely did just as you alluded that they might’ve done.
They were pioneers in the field!
Maybe Apple should require authentication to grant those permissions.... Of course, then we're back to the problem of password fatigue.