They tend to just say "we need this permission for the application/extension to
work correctly". And stop at this.
Seriously, a certain (quite famous, 5M installs) app got an update that requested a permission to install packages (!). It was actually harmless, as granting this won't work - the system won't allow this to non-system apps, but nonetheless it had just looked wrong.
I've emailed their support, asking why is it there. And - guess what? The reply was, essentially, "we need it because we do, it's required for the app to work, sorry but can't disclose the exact details". Well, polite, but essentially like this.
Long story short, I've accidentally mentioned this on a friend's blog, and my comment was noticed by his friend who had connections to the app's company (world's small, hah!) - so the ticket got elevated and took a proper review. Result is, this had just accidentally slipped from some dependency's development builds. Or something like that. Got apologies for the dubious response and a discount coupon, and the issue was fixed.
The thing is, it seems that a) I highly suspect, most users don't give a second thought about about accepting this permission (would there be more reports on this, I guess, the tier-1 support would know about the issue and the response would be different) and b) the initial attitude is "we know better".