In 99% of cases these devices are exploited using vulnerabilities in the software or configuration added by the vendor (such as telnet access with root:root), not bugs in Linux.
>open source
How exactly would a permissively licensed kernel get vendors to disclose the source code?
So even though current Chrome might be based on Chromium, Chromium was initially derived from Chrome.
That means somewhere down the line someone at Google must have suggested making a free version, probably out of enthusiasm for open source, and even though it buys Google little, the project was okay'ed.
I have no illusions about Chromium being independent, but as things are, Chromium development, in my opinion, is less commercially driven than Firefox development in spite of being a Google-driven project, allowing it to better serve its users with regards to freedom and the open web.
The main danger of Google's involvement is if Chromium would somehow outpace Chrome deployments, and them pulling the plug, but that's still very far away. And even then, due to its libre license, everything is far from lost.
You're right. It's just that the people who manage packages for those distros are actually sane. I can't believe people are still on kernel 4.4, or nodejs 0.10, or whatever.