The default certificate chain provided by Let's Encrypt currently still includes a cross-certificate from the expired "DST Root CA X3" to "ISRG Root X1" (the Let's Encrypt root) because:
Android did not trust ISRG Root X1 prior to version 7.1.1
Android intentionally ignores expiration of root...