Our recent improvements:
1) New USB-C port control setting integrated into the USB-C controller driver to disable USB at a hardware level. It will become "Charging-only when locked, except before first unlock" by default soon. Shipped in 2024022600: https://grapheneos.org/releases#2024022600.
@moonbolt Google was willing to consider this a valid vulnerability in our report to them about it despite the device admin API not really being designed with these use cases in mind. It's easy to replicate yourself.
We have a backlog of other vulnerabilities we need to report to them and we'll try to find time for it. The bounties they paid for this help to fund the time needed to report issues to them which is otherwise hard to justify rather than working on more GrapheneOS improvements.