"Remove malicious apps" doesn't undo the damage they caused. A reactionary approach only works until the first gigantic breach occurs, at which point people will finally start to ask "why do I have to give ShittyGame every permission under the sun?"
It's the same on Android. Why do I have to give any app that wants to display ads in my face permission to read my phone number and device serial number? Hell, on some carriers that's all you need to clone the phone and steal service from it. What possible reason could there be for that? It's poor design, and there's no reason I need to give "Bob's Fun Game" my telephone number just so it can have a unique ID to datamine later. Generate one on startup and use that.
The problems are similar and the solutions are similar - line-item veto for permissions, period. If your app can't handle it, crash - I'd rather have a broken app than risk my privacy for it.