When no one has met or even heard of anyone who was affected by running an outdated phone OS, they don't care if there's is outdated. Ask most random phone users, regardless of the OS, if their phone has current security updates, and they probably won't know what you're talking about. It doesn't really matter anyway, because your average phone user is far, far, far more likely to give away credentials through social engineering, or to be affect by a third-part data breach, than they are to be affected by the security of the software running on hardware they own.
Most phone security measures are security theater anyway, and state-sponsored organizations get around them with ease, which they only bother with because it is very important that the target not know they're compromised. Thieves stick to social engineering and stolen credit card numbers, because it's the easiest method.
It's no different than your house, where the door lock can be easily picked, but only someone committing a targeted covert break-in is even going to bother with that, because the regular thieves will just break a window.
Some of the following may be a little bit dangerous if connected to a network, but just make sure that it's a fairly locked down network, ie. fairly heavily restrict and monitor outgoing comms.
- LineageOS and relax
- "In case of emergency" device
- Portable entertainment-only device
- Offline authenticator app
- Offline crypto wallet (dangerous at the best of times)
- Webcam
- Backup 'target'
- Burner / Holiday phone
- Kids hand-me-down phone (duly sanitised)