Google’s Gemini Bug Lets Attackers Send Messages From Locked Android Phones
A newly discovered vulnerability in Google’s Gemini AI assistant allows someone with physical access to a locked Android 16 device to send SMS and WhatsApp messages without entering the phone’s PIN, raising fresh concerns about lock screen security.
According to security researchers, the flaw enables an attacker to impersonate the phone’s owner by sending messages directly from the locked device. The issue affects Android 16 devices where Gemini is accessible from the lock screen.
Researchers reported that the authentication bypass has been observed since May 2026. A security researcher successfully reproduced the vulnerability on a fully updated Google Pixel 6a using Gemini’s Deep Research feature as the starting point.
Although Google has previously patched several Gemini-related lock screen vulnerabilities, researchers continue to discover new methods of bypassing Android’s authentication protections.
How the Exploit Works
The attack relies on a specific multi-touch gesture.
Normally, if Gemini attempts to send an SMS while its access to the Messages app has been revoked, Android asks the user to enter their PIN before completing the action.
However, researchers found that pressing the “Continue” prompt and Gemini’s “Add attachment” button simultaneously bypasses the authentication check, allowing the message to be sent without unlocking the phone.
The exploit also allows attackers to reconnect Gemini to previously disconnected applications such as WhatsApp. By simply entering commands like “@WhatsApp” in Gemini, access can be restored without requiring the device owner’s PIN.
Even more concerning, these permission changes remain in place after the victim unlocks the phone. Users may later discover that Gemini has been granted access to apps such as WhatsApp despite never approving the changes themselves.
Physical Access Still Required
The vulnerability cannot be exploited remotely and requires an attacker to have physical access to the device. However, researchers warn that phones are frequently left unattended, temporarily borrowed, or stolen, making this type of attack a realistic risk.
Google Preparing a Fix
Google acknowledged the issue and confirmed that it is aware of the vulnerability. The company said a software update addressing the bug is scheduled for release during the week.
How Users Can Protect Themselves
Until the update is installed, Android users can reduce their risk by limiting Gemini’s lock screen capabilities.
To do this:
- Open the Gemini app.
- Tap your profile picture and go to Settings.
- Select Gemini on lock screen.
- Disable Use Gemini without unlocking, or at minimum turn off Make calls and send messages without unlocking.
Researchers noted that while Google is expected to patch this specific flaw, every new capability granted to Gemini on the lock screen increases the potential attack surface. As AI assistants gain deeper access to phones without requiring authentication, maintaining strong device security becomes increasingly
Leave a comment