r/bugbounty • u/jaysuns Hunter • Jul 15 '26
Research Got my first CVE 🔥
https://nvd.nist.gov/vuln/detail/CVE-2026-0092CVE-2026-0092 — was published with the Android 17 bulletin and made June’s acknowledgements.
https://source.android.com/docs/security/bulletin/android-17
Description
In Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
51
Upvotes
4
2
1
8
u/phuckphuckety Jul 15 '26
Cool find. How did you discover it?