Not only is it not reachable by anyone except your mobile provider, but every app is sandboxed anyway. Unless you're downloading random apps every day, why would you care? What do you think is going to happen? Just stick to reputable apps.
You know what I do on my still-supported phone? Set it up, then disable automatic updates, for both Android and the Play store. I update the browser weekly, but that's it. I update the whole manually after a few months or year if I feel I have a good reason to.
I can’t really speak about the cellular parts. (Although the fact that your SIM—including your eSIM—is a standalone computer with over-the-air installable applications, arbitrary access to the cellular network, and zero end-user ways to inspect it fills me with dread simply on general grounds. Oh and on all networks pre 4G the base station is not authenticated. And the auth implementations on 4G are often completely broken, especially once roaming enters the picture.)
But the Wi-Fi and Bluetooth stacks are wide open to everybody within 10s to 100s of metres of you who wants to grope them, every minute of your life. And given there’ve been pretty spectacular exploits by (smart and knowledgeable) randos even with the difficulty of reverse-engineering them as a rando, I feel fairly confident in expecting them to be a horror show internally.
Mind you, I’m not saying we shouldn’t complain to Google if we want them to transmit some backpressure on Qualcomm, just that basically the whole ecosystem is like this due to depending on a single chipmaker.
(In other news, Pixel 6 and later get three years of version updates and five of security patches; Pixel 8 and later get seven years of both. As far as I know, this us some sort of Google-specific sweetheart deal—other phones with Qualcomm consumer chips don’t get the same treatment.)