An Android phone comes with Google closed-source software operating on top of open-source Android. The same way that Chrome is Google's closed-source software on top of open-source Chromium.
So, in a way, all stock android devices are effectively compromised.
NSA > Shadow Brokers > Your Phone
>>513>horribly outdated softwareThis is the more obvious problem. Carriers can't be bothered to pay the cost for supporting failed updates, so they don't update. Many phones actually CAN'T run recent Android versions, as the hardware won't support it.