Has that changed or can you replace the OS in all phones, now?
Besides the article-mentioned /e/OS, there's also CalyxOS and GrapheneOS. GrapheneOS is seen as the top choice for tightest security, but also comes with the most downsides, being less compatibility with all your favorite apps, slower performance, lack of JIT compilation abilities (because it's unsafe), and, ironically, is completely limited to Google Pixel devices, which happen to have a black box "Titan" security chip that Google promised to open up but never did.
Why they think this unknown chip somehow makes the device more secure, I'll never know.
GrapheneOS also requires a lockable bootloader, because that is another attack vector. Malicious software could alter or downgrade the bootloader and load different software that could then spy on your device or read its contents.
Yet user-friendly Android options routinely tout features like "root access" and "unlocked bootloader" (LineageOS even requires it stay unlocked!)... but in reality these are enormous security holes that should not be there in the first place.
Just like how on the desktop... booting from recovery software or into a "single user mode" practically washes away all security and lets you access all the data. Besides encryption, things like Secure Boot and Mandatory Access Control should be used a lot more often to protect our data, but today unfortunately it is mostly relegated to mobile devices.