So every installation from an image will have the same UUIDs.
Yes
Is this a problem? Is there some security/privacy consideration here? Should there be some step in the centos-arm-installer script that changes the UUID and /etc/fstab?
Off the top of my head, I don't see any security issues. Do you?