Not that I know the entire implementation but I believe the phone has secure-element hardware that decouples sensitive material from the rest of the device. Therefore, in theory, attacking “the phone” gives you no access to (say) a credit card number. This should be a relatively small attack surface.
Nope, most android phones (that I'm aware of) lack a dedicated HSM. The iPhone 6+ was I believe the first general consumer phone that shipped with a HSM. Being a linux guy through and through, it is/was the reason I got a 6+ and I couldn't be happier. It isn't perfect, but it is a huge improvement over most other things out there.
Motorolla has the horribly overpriced AME 2000 (ick), and Samsung has the knox platform built standard into most of their stuff (which is very good), but they lack a true HSM. If you're an android user and want a HSM for sensitive data, get one of the Microcrypt SD devices. It is as good as you'll get (and still not as good as an iPhone).