Security-through-obscurity (i.e. using a custom ROM on a lesser-known device) does have some upsides, since you're less likely to be compatible with off-the-shelf exploits. But this is much less true now that LLMs exist, and anyone who can afford the tokens can port any exploit to any and all vulnerable devices.
Who maintains the kernel+driver trees used by the LineageOS port you're using? And what's the modem's security like?
Just gave me something else to be annoyed about today ("anyone who can afford the tokens can port any exploit to any and all vulnerable devices.")
Not sure that is exactly correct yet but guessing not long til it would be. Bleh.