How sensible and sensitive is our private world with Android devices? Is it optional to use Antivirus programs and VPN shields?

How vulnerable are these mobile devices? If I never root my devices or install APK from not especially trusted sources is my cellphone an open door to anyone with skills?