A malicious actor would need to be your phone manufacturer, Google or someone with a root exploit (jailbreak in iOS terms) or this "vulnerability" would be completely useless.
All of those parties could just as easily push code to your device any number of other ways that could do far worse than reading your logcat for BT IDs.
I understand the concern, but if you're at the point where you can't trust the parties who push automatic updates with high privilege levels but you do need to be concerned about reading logcat your threat model here is pretty strange.
However, if important data is retained in logs, then the manufacturer could grab the data from the logs. They can get information from a time before they decided to look into you.
It's like a wiretap vs access to a diary. A wiretap only gives you information after the tap has been installed, whereas getting your hands on someone's diary would give you access to previous information too.
If any Apple code that runs as root is evil, then your location data can be stolen in exactly the same way.
In the case of Android, the equivalent is code written by Google, the OEM, the chipset maker, and anyone those people gave root access to (which is often a long list of 'sponsorware' apps).
Overall, the class of vulnerability is the same, but Apple just does a far better job of vetting and controlling the list of people/code.
This as well as the extreme lack of trust for anything Google. Apple has an incentive to keep the privacy kick going, Google is already figuring out a way around Apple nuking ad identifiers. Trust is important.
You either have full access or you don't.