Why this matters
Attackers love application permissions because they apply to the whole tenant with no user present. AppRoleAssignment.ReadWrite.All or Application.ReadWrite.All on a forgotten app is effectively a Global Admin account that never signs in interactively.
Most apps need far less than they were given. Sites.Selected, Exchange RBAC for Applications and the OwnedBy variants exist precisely so you can grant the narrow thing.