CampaignSMS

Google fixing Android lock screen bug that lets Gemini send SMS without a PIN – The Register

TOPICS
Security
A specific multi-touch gesture bypasses an authentication prompt, allowing anyone to send messages
Picture this. Someone gets hold of your Android phone and, despite not knowing your PIN, they can use Gemini from the lock screen to send SMS or WhatsApp messages as you. This is a real bug and Google says a fix is coming as soon as this week.
Since May, The Register has received multiple reports of users bypassing device authentication on Android 16 devices that enable Gemini access from the lock screen.
These are distinct from the similar Gemini-based Android lock screen bypass bugs that have made the rounds since September 2025. 
One of the bugs reported to us allowed unauthenticated users with physical access to an Android device to enable functionality such as phone, texts, and WhatsApp via Gemini on the lock screen using a specific multi-touch gesture.
When device owners revoke Gemini’s access to certain apps, like Messages, and someone later tries to send an SMS via Gemini on the lock screen, the chatbot will prompt the user to open the relevant app. Selecting “Continue” prompts the user to enter the correct PIN to access messages.
However, when “Continue” is pressed simultaneously with Gemini’s “Add attachment” button, the device will then allow unauthenticated users to send that SMS via Gemini, without needing to enter a PIN.
From there, users can enable Gemini’s access to other apps, which were previously disconnected from Gemini in the user’s Settings, by invoking the relevant prompt.
For example, to allow Gemini access to WhatsApp, users can enter “@WhatsApp” in the Gemini text window. No PIN needed.
You can then check this has worked by going back into user Settings, after entering a correct PIN, and it will show that WhatsApp is connected to Gemini without completing the expected authentication step.
Exploiting the flaw requires physical access to a device. In most circumstances, we steer clear of giving this type of vulnerability too much airtime since it is often difficult to pull off in real-world scenarios.
If Windows, for example, had a make-me-admin bug that required the attacker, for whatever reason, to have physical access to the keyboard connected to the Windows machine, then the owner of said machine has bigger problems than the vulnerability itself.
However, given the state of phone theft crime, especially in the UK, and the potential to send convincing SMS messages as part of fake kidnapping scams, to name one possibility, we think this one deserves some attention.
A Google spokesperson told us this is a known bug and it has already implemented a fix that was scheduled for a full deployment this week.
They also said the bug is not Pixel-specific, after some claimed that they could not reproduce it on Samsung devices, but fell short of specifying which manufacturers, models, or versions are vulnerable. ®
Tim Lindholm, Java’s original JVM maintainer, shares with El Reg some of the grungy build details the doc glosses over
And what to expect in Firefox 153 as the next ESR release gets close
PARTNER CONTENT: How Envision is reversing the datacenter playbook by making computing chase abundant desert power, not the other way around
Amazon asks users not to panic as it works to fix the bug
Retail foundation leader Dave Treadwell takes over as senior leader and 19-year vet Dave Brown departs for pastures unknown
Turns out decades-old email tricks still work against some LLM-powered email filters
AI and ML
Data purges deemed an example of ‘misaligned behavior’ that upstart is working to avoid
AI and ML
Models demand trust without offering verification
SYSTEMS
Beware of fab makers bearing press releases
AI and ml
Thinking Machines’ first open weights model is a 975 billion parameter alternative to Chinese LLMs
ai and ml
One-two punch offers a glimpse of how low-precision AI can complement high-precision simulations
Security
PLUS: US takes down Iranian propaganda sites; Marketing company asks ‘Why Do We Have Your Information?’ And more!
Security
PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more
Black Hat and DEF CON
Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included
Security
Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified
Malware Month
On the plus side, infosec’s a good bet for a long, stable career
New Debian versions hit FOSSland in the form of 13.6 and 12.15
Flaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide
Joins yserver, Phoenix, and of course XLibre – and outlier Arcan
Next version of Linux Mint’s desktop has both kinds of display server
6.7 is now current, and in 6.8 you’re getting Wayland whether you like it or not
Now with Markdown support and smarter formula error handling – plus integrated AI, though it’s off by default

Biting the hand that feeds IT
Contact us
Advertise with us
Who we are
Newsletter
The Next Platform
DevClass
Blocks and Files
Situation Publishing
Cookies Policy
Privacy Policy
Ts & Cs
Do not share my personal information
Your Consent Options
Copyright. All rights reserved © 1998-2026.

source

Leave a Reply

Your email address will not be published. Required fields are marked *