I thought Apple was checking apps? How did this go through? In any sane jurisdiction exposing PII like that is illegal.
I don't think the App Store provider should be blamed for a security posture that is just wrong by design. The company is responsible to guarantee a meaningful degree of security for their user data.