Earlier quoted context omitted.
What does replacing the auth page gain the attacker? At worst the user enters their email address into a phishing page. The important thing is that there isn't a password :)
> What does replacing the auth page gain the attacker? If the spoof app has a "Connect with Twitter* (and you don't have the Twitter app installed), and then a webview is opened, the spoof app can replace Twitter's login page with their own, and capture the username and password.
While a malicious application can inject JavaScript to intercept the username, this alone is useless to an attacker.