The link referring to 7 years of update. If you follow the leaker on Twitter kamila in the original leak tweet they mention it can be 5 years of OS update + 3 years of security updates or something along the lines. The leakers isn't sure if it will be full 7 years of OS updates. I think other people reporting on the leak are failing to differentiate OS updates vs security updates making people to think Google rolled back on updates.
Is that still unpatched on the Pixel 6? As far as I can find the CVE has been patched in the Android security bulletin from 2022-11-05, which the Pixels receive (that + the patches specified in the separate Pixel security bulletin).
I don't really understand why you would spend Pixel 4 XL money on a phone that will only receive three years of updates, but it's not like Google hid their support timeline from any of their customers.