In addition, #Vanadium version 120.6099.230.0 is now available. This release adds the upstream fixes of 4 (3 high) CVEs, one allegedly being exploited in the wild.
Here is information by Google on these vulnerabilities for the Desktop equivalents:
https://chromereleases.googleblog.com/2024/01/stable-channel-update-for-desktop_16.html
As noted in the article, many of the Chromium security bugs are detected thanks to a variety of security technologies like Control Flow Integrity. While CFI is not enabled on almost all platforms, Vanadium enables it. In addition, Vanadium remains one of the only actively maintained browsers inheriting this feature on Android.
While the details of these CVEs are not entirely public yet, the fact they effect V8 could indicate a vulnerability incorporating JIT. Vanadium disabling this by default would have made their users already unaffected by this vulnerability if this turns out to be the case.
#GrapheneOS