This is beyond stupid how fucked up the phone market is. I'm still using my 2008 laptop with newest LTS (x)Ubuntu, but my 2018 Android phone lost official support in 2020... Thanks to that, now I have iPhone (longer support) and Fairphone 5 (I like how they try to upstream everything for this phone and promise really long support).
About your question: Should be fine. As long as browser is up-to-date, she doesn't connect to unknown WiFi networks/Bluetooth devices and she is not targeted. The easiest security fix is to not have anything worth anything on the phone :D