Novaliss did you read the report? The PoC is obviously not a malicious app per se, but what the report says is that apps can watch for events related to files in other apps' private storage. The vulnerability does not directly leak data, but functions as a side channel that can be used for behavioral tracking by seemingly benign apps without them asking for permission.
It is IMO something worth patching, in any case apps that relied on it were using it for malicious purposes. I assume GOS could implement a temporary patch, but we'd probably need to wait for upstream AOSP or Linux to do this properly.