Just to clarify that I specifically stated about safety in regards to drivers, firmware, and HAL's, many of which are clearly labeled as "closed-source". You can't blame GOS for being behind on such updates given Google's policies. Typical end users are in the dark on this. How would they know whether they are being attacked and how? Most issues with phones are user errors, connection errors, and application errors.
We'd need a ton of data to truly determine whether trusting Google over GOS for whatever period due to GOS being forced to be behind on driver, firmware, and HAL's updates. Topically, you could look at zero-day vulnerabilities in the past and see how many are OS-based and how many are hardware-based, but that doesn't tell you enough either. Where can one gather data on how often those zero-days were used, where, how, for how long, by whom or did the exploit involve someone pressing "Click here because I am a prince from Nigeria and I want to give your all my money" ?