The biggest threats haven't come from direct external assaults on the OS for years. I expect a typical consumer device is more at risk from an out of date browser than any other type of vulnerability now. The biggest risk for most of us as personal users is someone stealing our data via a hack, which often doesn't require root/administrator access to the host system anyway if you can compromise something already Internet-connected like a browser or messaging app.
Of course old versions of Windows not getting updates from Microsoft any more is a concern on some level but it's probably a long way down the list for anyone who actually has a good reason to still be using the old versions. I know quite a few people with quite a few different and entirely rational reasons for doing so, though many of those reasons involve some other form of predatory business model by some other big company that makes hardware and/or software. (Hardware that was declared EOL and doesn't have drivers for newer Windows versions, software with some sort of DRM that ties it to running on a specific system, that kind of thing.)
As I said before this kind of vulnerability is still a concern. Obviously it's a much greater concern if you're talking about something like a laptop that might be connected to an untrusted network, which would be crazy with an unsupported or unpatched OS. But for a home user who stays on their own network it's probably quite a long way down the list of things to be worried about.
So I get it, they bought the hardware with a one-time purchase. The maker moved on. One day the OS moves on.
But the hardware company is predatory for not writing a (free?) driver for their obsolete hardware on a new OS?
Surely if the model is "buy once" then there's no expectation to return to the well for "software updates"?
The solution is, as you noted, to freeze the OS. Which is perfectly fine, as long as you are happy doing that.
The rest of the world deals with this problem by adopting standards. There are plenty of peripheral makers in the PC world who could perfectly well have followed or established standards too and then their equipment might be useful indefinitely through generic, long-lived drivers. In reality many of them chose to use proprietary protocols with no public documentation available instead. Building in artificial obsolescence is certainly a predatory business model.