Most of the vulnerabilities require you to be loading sketchy apps, many of these are checked on Play Store by scanners, so unless you get very unlucky or sideload sketchy apps, probably not a concern. Web view and most other network exposed components are updated from play store, since stagefright they sandboxed all codecs, etc.
It's really not that bad for a typical user to just run an unpatched phone, certainly better than a Windows machine with local admin where downloading and running one executable is all it takes. At least on an unpatched Android device they get some level of sandboxing.