One of the so-called 'missing' CVEs (CVE-2015-6609) was discovered by the founder and original lead developer of GrapheneOS in *2015*. The methodology here was so poor it is making false measurements for vulnerabilities the project disclosed.
https://source.android.com/docs/security/bulletin/2015-11-01#acknowledgements
https://source.android.com/docs/security/bulletin/2015-11-01#acknowledgements
1❤️2