Google Racing to Fix Android Lock Screen Bug Allowing Unauthorized SMS via Gemini
Key Takeaways
- ▸A multi-touch gesture bypass defeats Android PIN authentication, enabling unauthorized SMS and WhatsApp messages via Gemini from the lock screen
- ▸The exploit requires physical device access but poses real-world risks including SMS-based scams and credential theft, particularly in regions with high phone theft rates
- ▸Google will roll out a fix this week and confirmed the vulnerability affects Android devices across multiple manufacturers, not just Pixel devices
Summary
Google is deploying a security fix this week to patch a critical vulnerability in Android that allows attackers with physical device access to bypass PIN authentication and send SMS or WhatsApp messages using Gemini from the lock screen. The exploit leverages a specific multi-touch gesture: pressing 'Continue' simultaneously with Gemini's 'Add attachment' button when attempting to send a message through a restricted app. Once the SMS authentication is bypassed, attackers can then grant Gemini access to other apps like WhatsApp by entering commands such as '@WhatsApp' without needing to enter a PIN. Google confirmed the bug affects Android 16 devices across multiple manufacturers and has been tracked since at least May 2026, representing a distinct vulnerability from previous Gemini lock screen bypass flaws discovered since September 2025.


