While I agree with you, they do in fact have hardware-backed key storage these days; it's just only available (and reliably useful) in recent Android versions (namely those devices with fingerprint sensors).
Since we're on the subject, OP was talking about a perceived vulnerability with rooted Android devices. I highly suspect that even a decent secure enclave solution would warrant some skepticism if the system around it is wide open. For example, timing attacks or even plotting voltage draw on an oscilloscope could leak some key information.
If you're rooting your device anyway, you should probably invest in a hardware security key.