Why is it surprising or even remotely controversial that an app that people explicitly authorized to access their messages (informed consent) then proceeded to access their messages? The app didn't have access to friends' messages, so I don't see what the issue is here, other than yet another clickbait headline.
For people I've discussed with, the surprising part is that they can do anything with it. You and I know that (currently) if someone has the data, they'll scrape/manipulate it at will. I believe, a reasonable person, would expect the limits of the access grant to end with the purpose of the app (a quiz) and not extend any further. Most contracts/agreements have limits and this one is implicit in the working of the ap…
You had to authorize the messages permission separately from all other permissions. If you didn't want your messages accessed, you simply declined that permission. This one's on the user, not on anybody else.