They’re all evil. Not worth it unless you’re planning to run Graphene IMO. The telemetry is insane. CVEs are kinda a toss up between the two the last few years, and counting CVEs is not a good metric.
My takeaway is run what you like unless your threat model is elevated. Lock down your Android or iPhone if you’re moderate risk. Run Graphene if you have any need of guarantees.
Article highlighting telemetry issues. Not conclusive, more just to illustrate that both options imply a trade off we’d all rather not make.
https://www.techspot.com/news/89130-research-shows-android-handsets-share-20-times-more.html