1) Opaque/centralized mass profiling
2) Insufficient epidemiological/practical efficacy
3) Everything related to how governments implement them, e.g. making them (de-facto) compulsory
4) Mission creep
G/A probably have still access to some data. They must amend their ToS with legally binding statements that STRICTLY prohibit them from exploiting any of it. In this case, (1) is perhaps largely resolved.
So, I currently see (3) and (4) as main issues.
Those may largely depend on the degree of authoritarianism and the health of public debate in a country.
Of course, also private institutions e.g. employers could make such an app (de-facto) compulsory.
They may still misuse their ToS/design power, and eventually even become identity providers for certain measures 🥶
It's complicated.