Google fixes dangerous Android flaw that allowed Gemini to send messages without unlocking the device

19.07.2026 2 minutes Author: Newsman

Google is rolling out a fix for a dangerous Android 16 vulnerability that allowed attackers to bypass the lock screen using Gemini. The flaw enabled anyone with physical access to a device to send SMS and WhatsApp messages without entering the PIN code.

The issue is tied to how Gemini functions on the Android lock screen. If a user had previously revoked Gemini’s access to the Messages app, any attempt to send an SMS would prompt the assistant to open the app instead. After tapping “Continue,” Android was supposed to require the device’s PIN before proceeding, and under normal circumstances, it did.

However, researchers discovered a way to bypass this security check. By tapping the “Continue” and “Add attachment” buttons in Gemini at the same time, they were able to trigger a software flaw that caused Android to skip authentication altogether. As a result, messages could be sent without unlocking the device.

The attack did not stop at sending messages. Using the same technique, an attacker could restore Gemini’s access to other apps even if the device owner had intentionally revoked those permissions. In practice, nearly any permission request made by Gemini could be approved without entering the device’s PIN.

According to researcher Mallory, the vulnerability also enabled several other unauthorized actions. An attacker could view or delete Gemini chat history, change certain security settings, and access sensitive data without knowing the device’s unlock code.

The flaw was successfully reproduced on a fully updated Pixel 6a, indicating that it affected devices running the latest available Android security patches.

Researchers believe the issue stems from the way Gemini interacts with Android when transitioning from the lock screen to full app access. During that handoff, the authentication process could fail, allowing the lock screen protections to be bypassed. Google is already rolling out a fix to address the vulnerability and prevent Gemini from being used to circumvent the lock screen.

Subscribe
Notify of
0 Коментарі
Oldest
Newest Most Voted
Found an error?
If you find an error, take a screenshot and send it to the bot.