Hungary-based researcher David Schütz reported the high-severity bug, tracked as CVE-2022-20465, which is described as a lock screen bypass due to a logic error in the code that could lead to local escalation of privilege with no additional execution privileges needed.Although the exploit does require an Android device to be in the attacker's possession, it's an effective way of circumventing a screen lock secured by a PIN, shape, password, fingerprint, or face.After connecting the charger and rebooting the device, the Pixel asked for the SIM's PIN code, which is separate from the lock screen code; it's designed to stop someone from physically stealing your SIM and using it.But instead of seeing a request for a lock screen password, the Pixel only asked for a fingerprint scan; Android devices ask for passwords/PINS after a reboot for security reasons.Eventually, he found that reproducing these actions without rebooting the device enabled a full lock screen bypass—not even a fingerprint was required."