Earlier quoted context omitted.
Even if spoofed, a MAC has to be (locally) unique or else you run into all kinds of network issues. As for spoofed on phones, maybe if you have root. But i doubt it comes spoofed out of the box (at least i have never heard of such a thing).
As of last year iOS devices do randomize their MAC address when polling for nearby WiFi, specifically to foil this kind of tracking. Here's an interesting breakdown of what is actually happening: http://blog.airtightnetworks.com/ios8-mac-randomization-anal...
This all sounds pretty good to me. Short-term tracking like this is useful and not very invasive. The randomization will still defeat long-term invasive tracking, like a store recognizing you from past visits and building up a database of your individual activity from that.