vulns.co
/
GKData.io MCP

IDAuthentication and identity · 2 min read

Pixel lock-screen completion lost security-state binding

A researcher-published vendor decision documents a USD 70,000 award for CVE-2022-20465.

Read the primary source IDAuthentication and identityReviewed 2026-10-02

Root cause

The researcher’s patch analysis attributes the issue to completion events dismissing a different active security challenge after concurrent state changes.

Demonstrated impact

Physical access could bypass the lock screen on tested Pixel 5 and 6 devices. Broader Android coverage was not established by the researcher.

Lessons for review

  • Bind authentication completion to the exact challenge and security context it satisfies.
  • Model concurrent authentication-state transitions and reject stale completion events.
  • Distinguish a security patch-level label from the date an update reached devices.

Award and evidence

USD 70,000Bug Bounty · Researcher Reported With Vendor Quote

Explicit USD decision for this report. It was initially marked duplicate; the reproduced response explains an exception because the report enabled remediation. Cash receipt is not separately documented.

Read the researcher article, full reproduced report discussion and vendor bulletins; checked the explicit award decision and unique CVE. Cross-checked the Google-authored CNA record publication date.

  • The award decision is reproduced by the researcher, not independently published by the vendor.
  • Payment completion is unverified.
  • Vendor patch-level labels and bulletin publication dates do not establish each device’s update deployment date.

Recorded timeline

Published
2022-11-10explicit
Public Disclosure
2022-11-08explicit · CVE record publication. The Android bulletin is dated November 7; its original snapshot was not retrieved, so first appearance of this entry is not asserted.
Reported
2022-06-13explicit
Awarded
2022-10-12explicit
Fixed
2022-11explicit · Reported fixed in the November update. The 2022-11-05 patch-level label is not used as an exact rollout date.

Sources and provenance

  1. Accidental $70k Google Pixel Lock Screen Bypass David Schütz · reviewed 2026-10-02
  2. Report 0016: Complete Lock Screen Bypass on Google Pixel devices David Schütz · reviewed 2026-10-02
  3. Android Security Bulletin, November 2022 Android Open Source Project / Google · reviewed 2026-10-02
  4. Pixel Update Bulletin, November 2022 Google · reviewed 2026-10-02
  5. Google Android CNA record for CVE-2022-20465 Google Android CNA, distributed through the CVE Program · reviewed 2026-10-02

Record reviewed 2026-10-02. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software