> qtwebengine-opensource-src No security support upstream and backports not feasible, only for use on trusted content
The fact that Firefox and Chromium are kept up-to-date with security patches represents a carve-out from the normal Debian security process (ability to build without fully packaging the dependencies).
This may also be partly related to Qt's security backports only existing on commercial LTS branches and not the public LGPL branches.