I guess that makes sense. Since most non-privacy-focused Android distributions don't let users turn off the internet permission, keeping the permission secure likely ceased to be a priority.

The full list of bypasses is likely much larger because it doesn't fall in the scope of bug bounties.

permission.INTERNET has _never_ been a dangerous permission on android.