> Who maintains the seucirty fixes in the bundled copy of webkit in chromium? Google?
In my picture yes. It is their choice to bundle a library and assume the responsibility for it rather than use the system version. And the distribution will do stability testing and supply upstream with fixes as now, as far as upstream plays responsibly, and at the same time they will provide their users with the information they need to judge how much of a security risk they are taking by installing Chromium. And Google will no longer have the distribution conveniently taking responsibility in front of the user for the security aspects of their (Google's) decisions.