CampaignSMS

Android Bug Allowed Gemini To Let Anyone Send Messages From Your Locked Phone – ETV Bharat

National
ETV Bharat / technology
By ETV Bharat Tech Team
Published : July 20, 2026 at 2:51 PM IST
Hyderabad: Google has confirmed it is rolling out a fix for a security bug in Android 16 that allowed anyone with physical access to a locked phone to send SMS and WhatsApp messages using Gemini without entering a PIN. A Google spokesperson told The Register that a fix has already been implemented and is “scheduled for a full deployment this week.”
While a Reddit user commented that the exploit did not work on their Samsung device, the Google spokesperson noted that the bug is not specific to Pixel phones, as reports indicate the vulnerability actively affects Pixel 6 series devices (specifically reproduced on the Pixel 6a). The spokesperson did not specify, which manufacturers, model, or versions are vulnerable to the exploit under the video demonstration.
What is this Android bug?
According to The Register, the publication has received multiple complaints since May regarding users bypassing device authentication on Android 16 handsets where Gemini remains active on the lock screen. The vulnerability relies on a specific multi-touch gesture rather than a broader system failure. Similar Gemini-based Android lock-screen bypass bugs have reportedly been surfaced since September 2025.
How the exploit works?
One of the bugs reported to The Register showcased how unauthenticated users with physical access to a locked Android phone could access apps like Phone, Messages, and WhatsApp via Gemini using specific multi-touch gesture.
In a YouTube demonstration, when a user tried to send an SMS via Gemini from the lock screen, the AI assistant prompted them to open the Messages app. The lock screen then displayed a “Continue” prompt, asking them to enter the PIN to proceed.
However, by using a multi-touch gesture to press “Continue” and Gemini’s “Add attachment” button simultaneously, the user successfully bypassed the lock screen. The device then displayed a list of contacts ready to receive SMS messages. Furthermore, the video demonstrated that simply typing “@WhatsApp” into Gemini’s text window granted access to the application without requiring a PIN code.
Why this bug is dangerous?
Once inside, an attacker can restore any of Gemini’s previously disabled permissions using the same exploit. Security researchers note that this allows unauthorized individuals to view or delete chat history, alter assistant settings, and extract private data—all without unlocking the device. The vulnerability reportedly worked even on a fully updated Pixel 6a, meaning standard system updates failed to prevent it at the time of discovery.
Researchers believe the flaw lies in how Gemini’s Deep Research feature and lock-screen app-handoff process manage authentication when transitioning from a locked state to full app access. While exploiting the bug requires physical access, experts warn it poses a significant threat amid rising smartphone thefts. A stolen device could allow criminals to send fake kidnapping threats or phishing messages to a victim’s contacts for extortion.
Exploiting the bug still requires physical access to the device, but researchers warn this makes it a serious concern amid rising phone thefts. A stolen, unlocked-adjacent phone could allow criminals to send fake kidnapping threats or phishing messages to a victim’s contacts, potentially for extortion.
How to protect yourself from this bug?
Until Google’s official patch is fully deployed, you can protect your device by disabling Gemini’s lock-screen permissions using these steps:
Step 1: Open the Gemini app.
Step 2: Tap your Profile picture or initial in the top right corner (or tap the three horizontal lines menu icon on the left).
Step 3: Select Settings.
Step 4: Tap the Gemini on lock screen menu.
Step 5: Toggle off “Use Gemini without unlocking”
Step 6: Toggle off “Make calls and send messages without unlocking.”
For All Latest Updates

Copyright © 2026 Ushodaya Enterprises Pvt. Ltd., All Rights Reserved.

source

Leave a Reply

Your email address will not be published. Required fields are marked *