- Edited
Myth is the wrong word. Open Source exists, there are benefits and drawbacks like anything else.
Nobody is expecting FOSS project code to be read by everyone who uses it. It is about community. Knowing that there are at least some people looking at code, is a huge benefit to everyone else.
Trust is never absolute. You don't have to trust a specific code auditor, because there are many. If someone tries to put in a backdoor in an open source project with decent popularity, it will likely be found sooner than later.
The more popular a project gets, the more independent people will look at the code. Whether for contributions, or finding vulnerabilities, it is a tangible benefit that closed source lacks. With closed source, you must trust a single entity. For Google, we all agree their quality is top notch. Privacy and data sharing however, is another matter.
Even with Google, although mostly proprietary and closed, they do have AOSP. The clue is in the name. This "Open Source Project" is what allows developers to make the modifications they need to bring us GrapheneOS.
If you didn't care about Open Source and want to trust Google over open source devs, then you would not be running GrapheneOS.