Root cause
The researcher’s patch analysis attributes the issue to completion events dismissing a different active security challenge after concurrent state changes.
Demonstrated impact
Physical access could bypass the lock screen on tested Pixel 5 and 6 devices. Broader Android coverage was not established by the researcher.
Lessons for review
- Bind authentication completion to the exact challenge and security context it satisfies.
- Model concurrent authentication-state transitions and reject stale completion events.
- Distinguish a security patch-level label from the date an update reached devices.
Award and evidence
Explicit USD decision for this report. It was initially marked duplicate; the reproduced response explains an exception because the report enabled remediation. Cash receipt is not separately documented.
Read the researcher article, full reproduced report discussion and vendor bulletins; checked the explicit award decision and unique CVE. Cross-checked the Google-authored CNA record publication date.
- The award decision is reproduced by the researcher, not independently published by the vendor.
- Payment completion is unverified.
- Vendor patch-level labels and bulletin publication dates do not establish each device’s update deployment date.
Recorded timeline
- Published
- 2022-11-10explicit
- Public Disclosure
- 2022-11-08explicit · CVE record publication. The Android bulletin is dated November 7; its original snapshot was not retrieved, so first appearance of this entry is not asserted.
- Reported
- 2022-06-13explicit
- Awarded
- 2022-10-12explicit
- Fixed
- 2022-11explicit · Reported fixed in the November update. The 2022-11-05 patch-level label is not used as an exact rollout date.
Sources and provenance
- Accidental $70k Google Pixel Lock Screen Bypass David Schütz · reviewed 2026-10-02
- Report 0016: Complete Lock Screen Bypass on Google Pixel devices David Schütz · reviewed 2026-10-02
- Android Security Bulletin, November 2022 Android Open Source Project / Google · reviewed 2026-10-02
- Pixel Update Bulletin, November 2022 Google · reviewed 2026-10-02
- Google Android CNA record for CVE-2022-20465 Google Android CNA, distributed through the CVE Program · reviewed 2026-10-02
Record reviewed 2026-10-02. Snapshot d5550c789111. Open the complete JSON contract.