CampaignSMS

Android lock screen vulnerability allows Gemini to send messages without PIN – SC Media

(Adobe Stock)
A security flaw in Android devices allows unauthorized users to send SMS and WhatsApp messages using Gemini from the lock screen, even without knowing the device’s PIN. Google has acknowledged the vulnerability and plans to release a fix this week, based on information published by The Register.
The vulnerability requires physical access to an Android device and involves a specific multi-touch gesture. Users can exploit this by simultaneously pressing Gemini’s “Add attachment” button and the “Continue” prompt when Gemini requests access to an app like Messages. This bypasses the PIN authentication, allowing an attacker to send SMS messages. Further exploitation can grant Gemini access to other applications, such as WhatsApp, by typing “@WhatsApp” in the Gemini text window, again without requiring a PIN.
While physical access vulnerabilities are often downplayed, the potential for misuse in scenarios like fake kidnapping scams, especially given the prevalence of phone theft, warrants attention. Google has confirmed the bug is not specific to Pixel devices and has implemented a fix scheduled for deployment this week.

Source: The Register



On-Demand Event
On-Demand Event
On-Demand Event

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

Related Terms

You can skip this ad in 5 seconds
Copyright © 2026 CyberRisk Alliance, LLC All Rights Reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorization.
Your use of this website constitutes acceptance of CyberRisk Alliance Privacy Policy, Editorial Policy, and Terms of Use.

source

Leave a Reply

Your email address will not be published. Required fields are marked *