They still do security fixes for iOS 15 which is the iphone 6S in 2015 so 8 years.
The last security update for iOS 12 was 7 months ago too.
IMO that's a generous period for security updates.
Their usefulness is honestly more limited by app developer's support of the old api's, and the increasing bloat of web apps rather than Apple's support. It would be better of course if we could homebrew on them after that but I'm not sure I'd call it pitiful.
FWIW, iOS 15 updates are still being released for these devices. A. week ago[1], in fact.
AFAIK every app that uses the ImageI/O api is effected by it, which includes every app you mentioned. You often don't need to even open the message for the image to be decoded.
From my understanding most vulnerabilities are from either the image decoder, text decoder, or webkit which again, effects nearly all apps. All apps can only use the webkit view, which affects nearly all of them to some degree.
I think you might be confusing the attack vector - messages is the easiest to attack since you just sent a regular text. Even if you don't normally use messages, it'll parse the image and you'll be hit by the 0 day. In theory this will work with most messaging apps.
But even if we allow that, that’s a completely distinct topic, and my point stands; your Python/Ubuntu comparison was still clearly unreasonable.
I have a 7.5 year-old iPhone SE and it has gotten two security updates this past month. In other words, the 5 years you mention is ONLY for entirely new OS versions which old hardware simply can't support. Older phones continue to be supported.