Case in point : Google Project Zero's latest iOS Exploit chains on webkit shows how easy it was(*is?) for an iOS user to fall victim to browser vulnerabilities by just visiting a website.[1]
The exploits covered targeted only 64-bit, so technically devices < iPhone5S which were not part of the update cycle wasn't mentioned in the GPZ research. But many of the exploit chains did use public jailbreak exploits and Semi-unthethered jailbreaks exist for 32-bit iOS devices running up to iOS 10.3.3.
I don't know whether complete exploit chain as detailed in the project zero wasn't possible for 32-bit devices or the attackers just didn't care about those devices. It is safe to assume, they are vulnerable.
Where as a 7 year old android device can still download Firefox for Android with latest security updates.
In any case, I don't think there can be any opposing arguments on the side of security for Apple not updating Safari via AppStore or now allowing proper 3rd party browsers.
[1]: https://googleprojectzero.blogspot.com/2019/08/a-very-deep-d...