You put in your username and password and the site reports back to the app saying, 'Yes, we know this person and have confirmed she is who she says she is. When you choose to sign into an app with either Google or Facebook, the login dialog box that pops up is actually provided by that company, not by the app you're trying to open. In essence, Google and Facebook are vouching for you. So, using your Google credentials to log in to other apps doesn't present a new security threat beyond what already is possible for a hacker with your password. That will then be sent to the email he just hacked into.
If a malicious actor gets your email password, he can request a password reset link for any apps you use. When it comes to Gmail, your password kind of already is a hacker's way into everything. But what if your password gets stolen? Doesn't that just give hackers access to everything instead of just one thing?