While its a good start (user separation among others), it doesnt address any core security issue, like timely kernel updates (and many phones don't even support OTA properly/don't get updates pushed, so no timely Android core updates either), sdcard security, drivers fully communicating in user space (this one won't be fixed as its a work-around to avoid GPL).
The kernel vulns are still there in most phones and exploitable from user space.
Have a look at the very new Android security review, by "experts" and official:
http://source.android.com/tech/security/index.html
While its a good start (user separation among others), it doesnt address any core security issue, like timely kernel updates (and many phones don't even support OTA properly/don't get updates pushed, so no timely Android core updates either), sdcard security, drivers fully communicating in user space (this one won't be fixed as its a work-around to avoid GPL).