Android itself is very bad security-wise. A lot of exploits are in the wild which haven't been fixed yet (Some of them won't get fixed in older versions).
If you are thinking about storing quite an amount on your mobile phone i would not recommend to do that. Its ok for everyday payments, but nothing which should be used to store long term.
In that case the attacker would have an overview of all of your transactions (incoming/outgoing).
He would completely infiltrate your privacy. But he can't spend any coins without the private keys.
But you are not vulnerable to any further attack, if that is what you have meaned.