This is a very big hypothetical.
They'd need to already have access to your account credentials (email, password or at least something that is regarded the same) then have you install this malicious app, then you'd need this app to be open at the same time as your 2FA app
It's possible, yes, it's an awesome find, yes, and this should be patches, yes yes yes, a thousand yes
Having said that, I'm not too worried about the potential impact of this, it'll be fine.