They're literally not upstreaming Android security fixes:
https://grapheneos.social/@GrapheneOS/117282080803799576
> Google should not be gatekeeping security patches to the standard Android platform code from Android OEMs but that's what they've started doing.
The whole Android developer verification program controversy.
These 2 are the recent things that come to mind that are most adjacent to "power-abuse".