If you turn off Android's setting to only allow app installs from the play store, then install a sketchy third-party store and download a flashlight app with a huge permission list that scrapes your email address book and sends it off to Russia, is that really a hack? It's pretty tough to prevent that without locking the phone down even harder than the iPhone. Doesn't seem worth worrying much about to me.
Android seems to be pretty safe against more dangerous stuff like visiting a website or displaying a web ad installs an app, bypassing user approval. Or worse, doing something with root permissions. At least I haven't heard of anything like that. If it's out there, presumably whoever has found such exploits keeps them under wraps for high-value targets.
The Stagefright one sounded pretty dangerous, but I haven't heard of any large-scale attacks with it in the wild. Presumably carrier-level general protections against mass MMSing and specifically against payloads for that bug were effective.
Given the difficulties the Android rooting community seems to be having, it's hard to believe that a drive-by exploit could gain persistent root.