Good question,
Simple answer:
If you stick to Play Store and your mobile number is not listed in the dark web, I wouldn't bother.
Users are the weak link always:
- Clicking on a link we should not.
- Downloading a file we should not.
- Installing an app we should not.
Now, if you are a targeted individual, then you need to hire a cyber sec expert to build you a tailored opsec. It will be worth it and is most of the time more affordable than expected
