Slashdot’s summary says it all:
“A Facebook app[/quiz/whatever] can get its grubby little hands on [lots of stuff] by recursively sweeping through your friends list, pulling all their info and posts, and showing it to you. What’s more, apps can get at your information even if you never run the app yourself. Facebook apps run with the access privileges of the user running it, so anything your friend can see, the app they’re running can see, too.”
See also: Facebook Quiz about Facebook Privacy, or the lack thereof.