Apps can easily be redesigned with some kind of webview integration, and some apps already do have random things that bring up webview, and thia would kill them on a rooted device.
The inherent issue here is they're arguing this will help prevent fraud, but they're not looking for fraud. They're looking for an altered device and assuming fraud.