LuckyLuke Now, what happens if we add some FOSS applications like Signal and K9 Mail? Will the 3 "evil" applications also communicate with my FOSS applications?
That's the thing. You won't know for certain without reviewing the source code for each and every open source app, after each and every app update. Apps can push/pull information to/from other apps via IPC so long as there is mutual consent between the apps.
For example, it was recently discussed in this forum how one app on the user's phone was delivering Google ads, even though the app itself had no network permission. This was due to the app's ability to deliver ad services via Play, which did have network permission on the device.
For most users of closed source apps, it isn't possible to know what, if any, data is shared between apps via IPC. For open source apps, you either have to blindly trust that data isn't shared, or do your due diligence and review the source code to ensure data isn't shared.