Gemini Lock-Screen Bug Let Android 16 Send Messages Without a PIN
A lock-screen flaw reported in July let someone with physical access to an affected Android 16 phone use Gemini to send SMS or reconnect WhatsApp without entering the device PIN. Google told The Register that it had implemented a fix and scheduled full deployment for the week of July 17, but the retrieved reports do not independently verify that rollout is complete.
A lock-screen authentication flaw reported on July 17 allowed a person holding an affected Android 16 phone to use Gemini to send an SMS without entering the device PIN. The bypass required Gemini access from the lock screen and a specific multi-touch action during the handoff to a messaging app.
Google told The Register that it knew about the issue, had implemented a fix, and expected full deployment during the week of July 17. The company also said the issue was not limited to Pixel phones, but it did not identify every affected manufacturer, model, or software build. The retrieved reports do not independently confirm that the planned rollout has reached every affected device.
How the bypass worked
The reported sequence began after a device owner had disconnected Gemini from an app such as Messages. From the lock screen, a request to send a message prompted Gemini to open the relevant app, which should have required authentication. Pressing Continue at the same time as Gemini's Add attachment control could bypass that PIN step and allow the message to be sent.
Reports from The Register, PhoneArena, and Cybernews also described a related permissions problem: entering @WhatsApp in Gemini could reconnect WhatsApp without the expected authentication. Exploitation required physical access to the phone and the relevant Gemini lock-screen configuration. Public reporting did not establish a complete list of vulnerable devices, so the finding should not be generalized to every Android 16 phone.
What users and mobile teams should take from it
Until the update status is confirmed on a specific device, users can reduce exposure by disabling Gemini use while the phone is locked or disabling calls and messages without unlocking. Mobile security teams should treat assistant-to-app handoffs as authentication boundaries: a PIN check must be enforced by the system, not only by a user-interface dialog that can lose focus during a multi-touch interaction.
The incident is a reminder that lock-screen convenience features inherit the permissions of the services they can invoke. Testing should therefore cover simultaneous input, state transitions, and previously disconnected apps—not only the normal one-button path.
Key Points
- 1The reported Android 16 flaw required physical access and a specific multi-touch gesture during Gemini's lock-screen app handoff.
- 2The bypass could send SMS messages or reconnect WhatsApp without the expected PIN check on affected configurations.
- 3Google said a fix was implemented and scheduled for the week of July 17; the retrieved reports do not verify universal rollout completion.
Scoring Rationale
The flaw crossed a mobile lock-screen authentication boundary and enabled impersonation from a physically accessed device. Its practical scope is bounded by required physical access, configuration conditions, an unspecified affected-device list, and an unverified rollout-completion status.
Sources
Public references used for this report.
Practice with real Ad Tech data
90 SQL & Python problems · 15 industry datasets
250 free problems · No credit card
See all Ad Tech problems