1) If that happens, I suspect the news will instead be "Massive data-stealing/phone-bricking/money-stealing worm for Android phones!!", not "${all that} for phones from OEMs which ship massively outdated versions of Android! (which BTW is nearly all of them)". It seems like something Google should want to put some pressure (or give some assistance to) the OEMs in order to avoid having that news release actually happen...
2) How are users even supposed to know if there are any security holes in their phones that their OEMs haven't fixed if Google doesn't release advisories?