I agree with your android statement. However, free software doesnt always mean open sourced. Ccleaner and malware bytes are examples of this.
Android is an interesting use case though. I will need to do some research. Do you know if the stagefright vulnerabilities were in the open or closed side of Android?
RE: Are open-source projects more or less secure than proprietary ones?