>It was Facebook's fault for exposing excessive data to users' friends during the Cambridge Analytica scandal
I don't follow this logic at all. The data shown to users' friends is the same data that is shown to them now. Which is usually all their public photos (nothing from private albums), the friend list (if they didn't make it private), etc., only the stuff that friends are expected to be able to access (and still can). And on the list of permissions on the permission request page, the app had a separate line for "friends' info" specifically (just like it has for every single permission requested), so there was nothing sneaky about it. The CA app asked users to provide them the same data about their friends that they can see in the browser by visiting their friend's page (and page only, nothing private or your messages with them; basically, only the info that everyone in the same security group that you are in sees). The exact same set of data that the browser extension this whole thread is about is accessing.
With that error corrected, it sounds like you are arguing for the case that FB was not at fault during the CA scandal because of all those logical reasons you brought up, and then conclude that FB was at fault and CA was in the clear.
I am reserving my own judgement on who was at fault, but I hope you can see why your reply left me (and likely some other people) confused.
As a cherry on top, CA didn't acquire the data directly from the app, as it wasn't their app. They got the data later on from a research team at Cambridge University's Psychometrics Center, which was the one originally collecting it. Sounds eerily similar to the scenario at hand.