Google to Patch Gemini Flaw That Lets Locked Android 16 Phones Send SMS and WhatsApp Messages Without PIN

 

Google is preparing to roll out a fix for a newly identified security vulnerability in its Gemini AI assistant that could allow unauthorized users with physical access to a locked Android 16 device to send SMS and WhatsApp messages without entering the device's PIN.
According to reports by The Register, the flaw affects Android 16 smartphones where Gemini is enabled on the lock screen. The issue enables an attacker to bypass authentication and send messages while the device remains locked, posing a potential security risk for users.
The publication stated that it has received several reports since May highlighting the authentication bypass on Android 16 devices with Gemini lock screen access enabled. In May 2026, a security researcher also documented successfully reproducing the vulnerability on a fully updated Pixel 6a using Gemini's Deep Research feature.
Although Google has addressed similar Gemini-related lock screen vulnerabilities in the past, security researchers continue to identify new methods to bypass authentication. This latest issue differs from earlier Gemini lock screen exploits reported since September 2025.
The exploit relies on a specific multi-touch gesture. When Gemini's access to messaging apps has been revoked, attempting to send an SMS from the lock screen normally prompts users to enter their PIN. However, simultaneously pressing the "Continue" prompt and Gemini's "Add attachment" button reportedly allows the message to be sent without authentication.
Researchers also found that an attacker can reconnect previously disabled apps, such as WhatsApp, to Gemini directly from the lock screen. By entering prompts like "@WhatsApp" in Gemini's interface, the app can reportedly regain access without requesting a PIN.
One of the more concerning aspects of the vulnerability is that these permission changes persist even after the device is unlocked later. Users checking Gemini's settings may discover that apps like WhatsApp have been connected despite no authentication having taken place.
The attack requires physical possession of the affected Android device and cannot be executed remotely. However, security experts note that phones are often left unattended, misplaced, or briefly handled by others, creating opportunities for misuse.
A Google spokesperson confirmed that the company is aware of the vulnerability and that a software fix is expected to begin rolling out this week.
"A spokesperson at Google told The Register that this new bug is known about, and that a fix is scheduled to be rolled-out this week."
Until the update becomes widely available, users are advised to limit Gemini's lock screen capabilities. This can be done by opening the Gemini app, tapping the profile picture, navigating to Settings > Gemini on lock screen, and either disabling "Use Gemini without unlocking" or turning off "Make calls and send messages without unlocking."
The incident highlights the growing security challenges associated with AI assistants gaining expanded functionality on locked devices. As AI features become more capable without requiring user authentication, maintaining device security becomes increasingly complex.

This article has been indexed from CySecurity News – Latest Information Security and Hacking Incidents

Read the original article: