They lag 1-2 months behind the Android Security Bulletins which are months behind when patches can first be shipped by vendors. Verifying their kernels for the FP5 and earlier are end-of-life can be done by looking at the code. It's straightforward to verify they're a year or more behind on major updates and that those are required for full security patches. It's clear from a basic glance at the Android Security Bulletins that Low and Moderate severity patches are not backported. It's harder to demonstrate they don't backport all High and Critical severity patches but it's true and the gap of what's not backported is growing with recent changes. They made an announcement to OEMs about only the most recent 2 major yearly versions getting most High and Critical severity backports along with even those no longer getting a large portion of High and Critical internally found bugs which were found with LLMs.