Phones that can't get software updates are more at risk of becoming targets for malware. Many phones only get software updates for a small number of years, often three years or less. Usually they get only a short time of firmware updates, a somewhat longer time of first-party bugfixes, then merely app fixes and possibly third-party ROM fixes.
Yet modern phone hardware is often still plenty fast enough for everyday use when the updates dry up.
Hence my question: what is the actual real-world danger of not updating your phone? Did anything ever happen to you or your phone because it wasn't updated?
https://en.wikipedia.org/wiki/Pegasus_(spyware) used this among other exploits. "Once installed, Pegasus has been reported to be able to run arbitrary code, extract contacts, call logs, messages, photos, web browsing history, settings, as well as gather information from apps including but not limited to communications apps iMessage, Gmail, Viber, Facebook, WhatsApp, Telegram, and Skype."