This couldn't be more wrong. Android is an open source platform maintained by Google. However, in the wild it exists in four categories of flavors
- Android Open Source Project (AOSP) - open source plain android without any Google Play services. Operated under a BSD license by Google and security maintained by Google
- An open source platform. The Security community has not yet determined whether or not this is more or less secure than closed source platforms like iOS. Generally, experts suggest any advantages or disadvantages of open source vs proprietary software cancel each other out, thereby making them equally as safe.
- When other developers edit AOSP (for example, the Amazon Fire platform is built on AOSP), they introduce unmanaged vulnerabilities through their added code which Google does not patch.
- Android One - plain Android with Google Play services but no OEM software.
- This software model is considered secure because Google handles both the closed source (Google Play Services) and open source (AOSP) aspects of the device.
- This arrangement is very similar to the software arrangement of iOS, where one company manages ALL the software components. The only difference is AOSP is open source, which is NOT necessarily safer or less safe than closed source applications. Android One gets software updates for an allotted period of time.
- Android on Google Pixel - plain Android with Google Play services with a special launcher and added Google-specific features (Google Assistant, the Google Launcher)
- The safest Android experience. Pixels generally get all updates first
- Google maintains ALL hardware, software, and services on device
- Has Titan M designated for security
- Like iPhone, fingerprint is stored on device
- This is the experience we are discussing here.
- OEM specific Android Flavors - Based on AOSP with Google Play Services
- Google maintains Google Play Services security and AOSP security
- Generally, vulnerabilities are introduced by OEM software (custom launchers, custom software)
- All Google software updates need to be adapted for the OEM devices
- Less safe than Android One, Google Pixel is safer due to complete Google management
- No one is arguing here this is safer than iOS.
There may be more flavors (I think Android TVs fall into a different category and, like Carplay, Android Auto is based on QNX, I believe), but this is the way Android is now.
It's worth reiterating (again), Google doesn't market Pixel as an Android device. At the Pixel 3 launch, Android was said zero (0) times. It's a different, proprietary flavor based on open source code.
"Google" is not "android". They're different things. I may come off as rude but people come here and believe the ghost stories about Android without completely understanding the whole picture.