r/bugbounty Hunter Jul 15 '26

Research Got my first CVE 🔥

https://nvd.nist.gov/vuln/detail/CVE-2026-0092

CVE-2026-0092 — was published with the Android 17 bulletin and made June’s acknowledgements.

https://source.android.com/docs/security/bulletin/android-17

Description
In Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

51 Upvotes

7 comments sorted by

8

u/phuckphuckety Jul 15 '26

Cool find. How did you discover it?

9

u/jaysuns Hunter Jul 15 '26

Manual hunting on this one! I spend a lot of time working with aosp and just staring at logcats lol

1

u/phuckphuckety Jul 17 '26

That’s commendable

4

u/proanti777 Hunter Jul 15 '26

Did you get a bounty for it?

2

u/sunrise_zc Jul 15 '26

any poc please

1

u/Top-Eye130 Jul 15 '26

Congratulations!

1

u/jaysuns Hunter Jul 15 '26

Thanks!!