I think it's worth emphasizing how much people are being tricked.
Users are only being asked for permission to their "messages", are given no further information, and can not proceed if they do not submit to the request.
If you're a good hearted person, you assume that an app needs to use your messages for one specific purpose, much like some apps ask permission to your text messages just so they can automatically validate incoming sms code requests.
Anyway..
So permission to access your messages could mean "we just need to do one thing" or it could mean "we're going to siphon up all of your private data"
The generically worded option preys on the user to be trusting enough to give the other party the benefit of the doubt, which is not how the system should be handled and really is the entire focus of the GDPR being passed in Europe right now to prevent specifically this sort of thing from happening.
Waving 'user consent' around as a reason to do nothing is the wrong approach.