The story for security on Android is really, really sad. Google should be pressing really hard on the secure enclave button. Even game consoles have better security [here I wanted to add: "... than the most secure Android device", but that would be untrue, since I don't know all the Android devices out there. Let's just say the situation is sad, verging on terrible because it's Google, full of smart people who almost certainly know better].
Google probably can't get away with just trusting TrustZone, given the number of manufacturers of SOCs and the opportunity for the folks doing chip-level cut-and-paste of features to get things wrong.
I imagine there are patents in the way. Solve that with the realization that a united front against adversaries (crackers, state-level actors) is better than a fragmented one.
Solve the technical issues by getting the right 20 engineers in a room for a week or two, to set a proper direction. Android could have great security in a large set of phones inside of 18-24 months, with the right management.
Sigh.