I guess that makes sense. Since most non-privacy-focused Android distributions don't let users turn off the internet permission, keeping the permission secure likely ceased to be a priority.
The full list of bypasses is likely much larger because it doesn't fall in the scope of bug bounties.
The full list of bypasses is likely much larger because it doesn't fall in the scope of bug bounties.