Earlier quoted context omitted.
Because 80+% of users are on the latest os version and the inverse is true of Android.
This doesn't use an exploit in Android and instead runs payloads with the permissions of the app. The same can happen on iOS and very likely does in many apps but is reported less often because there is no economic incentive (the App Store doesn't allow antivirus services). For an example, see how Xcodeghost went unnoticed by Apple.
XcodeGhost was a compromised compiler suite. See https://en.wikipedia.org/wiki/XcodeGhost#Attack_vector