I checked my own device, and despite owning it just about a year, security updates have likely already stopped (although the manufacturer website hasn't exactly confirmed that, just yet) and even if the security updates were still coming, the gap between when they are released and then reach the devices are measured in months, not days, making these exploits worse than zero-days. I have seen no movement in correcting these issues from any of the manufacturers.
You too can check for yourself at source.android.com/security/bulletin
The exploit given here works on any device with the given driver, regardless of OS. Android is just the primary example since it is the 800lb gorilla.
And as the article mentions, just 2 hardware stacks make up nearly the whole ecosystem.
His writing is interesting anyways. Until I read this one [1] I didn't even know Snapdragon NPU has an open source driver. It's scary to see such a complex logic like NN graph execution running in the kernel space.
Which suggests that QA should do this, too.