Yes but Android phones get desperate security updates for apps now don't they. Apple just tends to do them in one big go.
Google has indeed been moving more and more stuff from core Android to Google Play Services, which updates through the Play Store and supports a wide range of versions (it wasn't long ago when they finally dropped 2.3). As long as the vulnerable component is under the Google Play Services umbrella, patching it won't be a problem. However, there are times when the vulnerability is in a component that's still bundled with the core Android itself, and in those cases an OS update is needed, and depending on the phone it could take quite a while or never appear at all.