As the quality of Android code gradually improves and mitigation measures strengthen, we observe an increasing difficulty in discovering security vulnerabilities that could have significant impacts in recent years. However, we still witness the continual emergence of new vulnerabilities in certain well-known attack surfaces. Does this suggest that we may have overlooked something? In this talk, I will draw from my own experiences to retrospectively review my research achievements in vulnerability discovery and exploration across various layers of the Android ecosystem over the past few years. I will specifically focus on two techniques — fuzzing and static analysis. The discussed vulnerability landscape encompasses privileged applications, service processes, system libraries, and ;)