I think the real question is what mechanism allows them to push a random app to some phones? google play services is actively listening for remote installation requests? that's essentially a remote-code-execution backdoor to all android phones?
No different than, say, "Windows Update". The entire "updates" culture is essentially RCE backdoor (botnet) functionality for "trusted" tech companies. Consent, where it is actually explicitly obtained, never rises to the level of "informed". That's because even if a user "consents", she still cannot see what is in each update.
In my case the maker of my motherboard installed a persistent “self-repairing” (i.e. difficult to uninstall) from yet another third party. Naturally, I will not buy a product from them (MSI) again.
Another way to put this is: windows update will install malware w/o user approval in the background.