In Android, browser, messaging app updates and many even system updates are delivered through Play store (long after system/OS updates have stopped for the phone), so attacks will have to be much more sophisticated.
Correction: 4A does not receive _some_ updates, namely OS level updates.
Other things like the recent 0days for Chrome are handled via the store and have already been updated.
I am not defending unpatched phones just to be clear, but its not end of the world if you use unsecure device, just keep all your money and other important stuff away from it. Which is fine for many people.