Last month, a cybersecurity firm discovered the first-ever Android malware that came with the capability to steal the 2FA (two-factor authentication) codes generated by the Google Authenticator app.
I've used Google Authenticator for years. It's not a default Android app, but I've used it for so many years at this point that it does just transfer from phone to phone, so it feels very much default ...