This story is bogus. The vulnerability lives in a demo app that’s disabled by default. Enabling that app would require the attacker to have physical access to the device and your passcode.
The folks at GraphebeOS have a thread about it: https://grapheneos.social/@GrapheneOS/112967309987371034