Is that true though? I do a lot of security work and iOS RCE vulns are typically patched same day with all devices in support getting that security patch at the same time.
Android, it’s heavily dependant on the device manufacturer etc, no? So many forks of Android plus countless handsets never get an update as they’re out of support.
And even from an OS architecture point of view, actual Android and its IPC via intents, content providers, broadcast receivers, and component exports etc is a whole world of juicy attack surface that simply doesn’t exist on iOS. Which is a primary reason people hate iOS given apps feel so isolated and you have to use the share sheet to get data between apps.
Then you have Android’s differing chipsets vs iOS’s Secure Enclave that’s on all supported handsets. Plus Android’s WebView has addJavascriptInterface() allowing native code execution via that API whereas Safari, as shit as it is, doesn’t have that enabled.
Don’t get me wrong, Android is an awesome operating system and it’s openness enables some amazing distributions like GrapheneOS.
But even a cursory glance at the two attack surfaces, iOS has a way smaller surface and swifter patching.