I know it's against the rules to tell people to read the article, but I would encourage everyone to read the article. It specifically says this is a potential threat to > "elected officials, candidates, political campaigns, [and] political parties" not to the general public. The potential threat is for someone at Candidate_1's campaign taking selfies with the app, that then uploads them to Russian servers where the R…
For example, I already have a database of high value target's faces built from political sources like house.gov. Now I do facial recognition between that set of faces and the FaceApp faces. That allows me to identify the specific devices used by government officials. That would seem to be super valuable for more targeted attacks and/or pairing with other apps for potential kompromat.