I haven’t fuzzed a C++ compiler myself, but our team recently tried fuzzing a relatively simple S-expression-based compiler and discovered several issues in a few weeks [1]. I can only imagine what could be uncovered in C++ compilers. If this hypothesis holds, it suggests a significant attack vector that might elude even the smartest security researchers who are only analyzing repository codes and dependencies.
[1] "Why the Fuzz About Fuzzing Compilers?": https://www.coinfabrik.com/blog/why-the-fuzz-about-fuzzing-c...