Earlier quoted context omitted.
That's only for 'dangerous' permissions as defined by Android. As an example: NFC is defined as a 'normal' permission.[0] As far as I'm aware [not an expert here], there's nothing stopping an app developer from updating their app with the ability to steal credit card/passport information (if the card is tapped against the phone). [0] https://developer.android.com/reference/android/Manifest.per...
Credit cards can not be duplicated wirelessly. I’m not familiar with passports but if they can then I’d say that’s a flaw of the cards rather than phone permissions. It’s possible to read nfc cards from quite a distance with a high power reader.
From a casual further inspection, there are videos on YouTube which demonstrate this: https://www.youtube.com/watch?v=K_6oMZb8UOI