I worked on #AOSP for 3 years. It's enough to know that there are millions of devices in the wild running ancient kernels with unpatched security holes.
Android system permissions add a second line of defense, but stores also use a combination of security reviews, developer reputation, user reports and static analysis tools to catch malicious apps and actively kick them out.