This is true. Most Android devices run forked kernels supplied by manufacturers. Once the manufacturers stop updating the kernel, the device is stuck using the old kernel forever. I have several phones running LineageOS that I use as remotes for my TVs, and they'll never see a kernel beyond the 3.x fork the manufacturers released 5+ years ago.
This issue is indicative of the larger problem ARM SoCs pose to consumers: manufacturers choose not to design ARM boards with SBSA-like features[1] because it's cheaper to do so. While x86 machines have enumerable buses for hardware discovery, as well as ACPI support, ARM SoCs don't. As a result, mainline Linux kernels won't boot on them, they require a kernel fork, and a kernel fork must be maintained. Manufacturers have no incentive to maintain that fork for more than a year or two.
As ARM SoCs take over what are considered general purpose computing devices, like laptops, devices that we once thought of as being upgradable, software-wise, suddenly aren't. Apple's M1 Macs are an example of this. To get Linux running on them is a massive undertaking, and running Linux on them in the long-term means relying on a third party to build and maintain M1-specific images in perpetuity, because the SoCs can't run the generic ARM images that ARM servers can run.
There are mitigations against this problem in Linux, like Device Tree[2] support, but that is only one small part of the big[2] undertaking when it comes to porting Linux to ARM SoCs.
[1] https://en.wikipedia.org/wiki/Server_Base_System_Architectur...
[2] https://en.wikipedia.org/wiki/Device_tree
[3] https://elinux.org/images/a/ad/Arm-soc-checklist.pdf