Public Wi-Fi: what can actually happen
What has changed in recent years
For a long time people repeated that on public wifi anyone could read your passwords. Today that is far less true, and it is worth saying: almost the entire web uses HTTPS, and the contents of your connections already travel encrypted end to end.
So no, someone at the next table is not going to read your email simply by sharing a network. That scenario has been heavily overstated.
What is still true
Where you go is visible, even if what you do is not. Whoever runs the network can log the domains you visit. Not the content, but the list. For many people that is already sensitive information.
Fake networks. Setting up an access point called Airport_Free_WiFi is trivial. If you connect to it, all your traffic passes through that person's equipment.
Manipulable captive portals. Those "accept to browse" screens are ordinary web pages, and not all of them are well built.
Badly configured services. Not every app on your phone uses HTTPS correctly. One that does not is enough.
Which measures genuinely help
Encrypt the path with a VPN. It solves the underlying problem: the network in between stops seeing the domains you visit, and it no longer matters whether the access point is legitimate.
Turn off automatic joining. Your phone remembers known networks and reconnects on its own. An attacker can advertise a network with the same name.
Do not dismiss certificate warnings. If the browser warns about a certificate problem, take it seriously and stop.
Keep the system updated. Unglamorous, but it closes most real holes.
In short
Public wifi is not the danger it is sometimes painted as, but it is not equivalent to your home network either. The practical difference is who can observe where you connect.
Encrypting that path is the measure that solves the most problems for the least effort.