Google’s Gemini Lets Strangers Send Messages from Locked Android Phone

A new vulnerability in Google's Gemini AI assistant lets attackers bypass the lock screen on Android 16 smartphones.

By Central
The exploit uses a multi-touch gesture to send messages without authentication on locked Android 16 devices.
Highlights
  • The flaw allows sending SMS and WhatsApp messages from a locked Android 16 phone without entering a PIN.
  • Attackers can grant Gemini permanent access to apps like WhatsApp, even after the device is locked again.
  • Google has acknowledged the vulnerability and is working on a patch, but users should disable Gemini on the lock screen.

A critical vulnerability in Google’s Gemini AI assistant is allowing anyone with physical access to a locked Android 16 smartphone to send SMS and WhatsApp messages without entering a PIN or password. The flaw, which Google has acknowledged and is currently working to patch, undermines the fundamental security of the device’s lock screen and exposes users to potential social engineering and impersonation attacks.

How the Gemini Lock Screen Bypass Works on Android 16

This latest exploit, which security researchers have been tracking since May 2026, represents a persistent and evolving threat to Android lock screen integrity. The vulnerability is not a new, isolated incident but the latest in a series of Gemini-related bypasses that have plagued the operating system since September 2025. The core issue lies in how Gemini handles authentication when performing actions from the lock screen.

The specific method for this exploit involves a precise multi-touch gesture. On devices where Gemini’s access to apps like Messages has been previously revoked, a standard attempt to send an SMS from the lock screen triggers a PIN prompt. However, by pressing the “Continue” button simultaneously with Gemini’s “Add attachment” button, the authentication check is circumvented, allowing the message to be sent without any credential verification.

Escalating Access: Connecting WhatsApp and Other Apps

The risk does not end with a single message. Once the initial bypass is successful, an attacker can then grant Gemini permanent access to other disconnected applications. By typing a command such as “@WhatsApp” into Gemini’s text window, the assistant invokes a prompt to connect the messaging service. Critically, this secondary action also bypasses the lock screen entirely, requiring no PIN entry.

What makes this attack especially dangerous is its persistence. The changes an attacker makes are not temporary. If the device owner later unlocks their phone and checks their Gemini settings, they will find that WhatsApp—and potentially other apps—have been granted access, even though the device was never unlocked. This allows an attacker to continue sending fraudulent messages from the victim’s accounts at a later time, without needing to repeat the initial exploit.

This latest bug is distinct from previous Gemini-based bypasses, which used the assistant’s ‘Deep Research’ feature as an entry point on fully patched devices, including the Pixel 6a. The iteration of flaws demonstrates that simply disabling specific Gemini features is not a comprehensive fix; the underlying architecture of the lock screen integration remains a target.

Who Is at Risk and What Makes This Attack Feasible

While this vulnerability requires physical access to a target device—ruling out remote, mass-scale exploitation—the attack surface remains significant. The scenario is common: a device left unattended on a desk, snatched from a bag, or handed to someone the user believes they can trust. In each case, the attacker can operate the phone without ever needing to guess a PIN or biometric scan.

The feasibility of the attack is heightened by the fact that many users enable Gemini’s lock screen access for convenience, valuing the ability to send quick messages or make calls without unlocking their phone. This convenience feature directly creates the attack surface that researchers have now found a way to exploit.

What Users Should Do Right Now to Secure Their Android Phone

Google has confirmed it is aware of this specific bug and plans to roll out a fix. However, until that patch is applied, users can take immediate action to neutralize the threat. The most effective step is to restrict or disable Gemini’s ability to operate from the lock screen entirely.

To apply this protection:

  • Open the Gemini app, tap your profile picture or avatar, and navigate to Settings.
  • Select “Gemini on lock screen.”
  • Turn off the option labeled “Use Gemini without unlocking.” For a more granular approach, disable the specific toggle for “Make calls and send messages without unlocking.”

Understanding the Deeper Security Problem with AI Assistants

Google will likely patch this specific multi-touch exploit. However, this recurring problem points to a fundamental security tension that is not going away. Every new capability granted to an AI assistant on the lock screen is also a new potential attack vector. The more useful and seamless an assistant becomes without authentication, the harder it is to guarantee that only the legitimate owner can control it.

The principle of least privilege applies directly here: a lock screen that requires a PIN for manual app usage but bypasses that check for an AI agent creates an inherent contradiction. The most secure configuration for any user is to require unlock authentication for all interactions, thereby eliminating the privileged execution path that the Gemini assistant represents.

How to Protect Against Lock Screen Bypass Attacks

Users should evaluate their device settings through the lens of a potential physical compromise. While it is convenient to ask Gemini to send a text, the security risk of that convenience is now clearly demonstrated. Until Google provides a permanent architectural fix that decouples the assistant’s power from the lock screen’s security, the safest approach is to treat the AI assistant as an extension of the device’s core security—and lock it down accordingly.

Share This Article