I do a lot of security work and iOS RCE vulns are typically patched same day with all devices in support getting that security patch at the same time.
The ones you know about, yes :). We know there are complete firms actively exploiting iOS devices though. With Android the security community can figure out what the flaws are and patch them, with iOS it's a black box.
Android, it’s heavily dependant on the device manufacturer etc, no? So many forks of Android plus countless handsets never get an update as they’re out of support.
Most devices are legally required to get X years of security updates, and most manufacturers do push those out fairly quickly. Maybe not all the same day, sure, but they do go out.
I do remember a fair few exploits for iOS devices that allowed an attacker to take over a device without any user interaction, and most mentioned they were actively being exploited by malicious (state) actors.
All I think however is that the price of the exploit doesn't necessarily correspond with how secure the device actually is, but rather it's based on the value that that exploit might hold. US entities would probably also offer more than EU entities, whereas for Android it might be the other way around.