I see lots of different explanations here but people seem to have missed the most important one:
ECONOMY!
Let me explain, because you are probably not thinking about the same thing as I am right now:
Android exists on different CPU architectures (ARM, x86, MIPS, ...) and from hundreds of different vendors. Even a single companys devices can differ slightly in what SoC (qualcomm, Samsung, mediatek, intel, ...) they use and what security functions have been added to the OS core. For example Samsung has additional hardware and software security functions in high-end phones. Google has some security stuff that started as software in early Pixel models but are more and more done in hardware or at least dedicated security cores in newer models.
Add to that different android and patch versions and a general tendency among users to ignore updates even when available and you end up with thousands of tiny differences that can make an exploit fail on the target machine.
This type of exploits must be reliable, you can't just spray millions of devices and be happy with a 10% success rate. You have one target and maybe only one chance to get it, as a failed attack may be noticed by the owner and the attackers really don't want that.
So the company has the choice of maintaining one set of exploits for latest iOS or hundreds for different android phones. It is simply not economically viable.