Reponsible nations should forbid to sell a phone without providing at least 7 years of updates. How that, we are living in free world? Obviously under environmental legislation, avoiding a lot of completely avoidable electronic waste. Some people break their phones much earlier, but far from all do.
Wouldn't that hinder technical progress? It might slightly slow down it. But looking at the current bloat of nonsense that a current Android phone contains, that would not be a bad thing. If you need more than 2GB of RAM for a phone to run smoothly it's just bad engineering.
To answer your question: This SailfishOS phone runs a 3.10 kernel. It was built only 2 months ago, but I would not bet my head it is really well-patched throughout. The browser is based on Firefox ESR 78. So although formally still maintained I'd not be surprised it contained unpatched known vulnerabilities. Nothing has happened to me ever, but I don't use this phone to do really sensitive stuff.
For a mainline Android phone the risk might be higher. What were the last big drive-by attacks not requiring user interaction?