

Lol, Play is an exploit.
After 30 years in IT, I’ve seen 100x more systems taken down by updates than by exploits.
Actually, I’ve never had a system taken down by an exploit, 100% of outages have been caused by borked updates or changes.
I’ve had friends who’s clients have been taken hostage by exploits, and 100% of those have been because of poor security practices and phishing - neither of which is preventable by updates.
Here’s a question, if almost no-one sideloads or uses FDroid, where do people get the millions of malicious apps from? Play Store.
So where’s the problem again? Oh, yea, Play Store.
Yep.
Rather than try to single-handedly re-engineer an old protocol to be secure, I just use it for stuff where security isn’t a big deal. Including messages with links to secure resources (and send credentials via a separate system).