Gemini bypasses PIN and sends SMS when lock screen exploit is triggered in Android

Viewed 2

On Android 16 devices with Gemini's lock-screen access enabled, an unauthenticated person with physical access to a locked phone can send SMS messages and access WhatsApp through Gemini without ever entering the device PIN. The bug also lets an attacker silently re-enable Gemini's access to apps (e.g., Messages, WhatsApp) that the owner had explicitly revoked. Google has confirmed it as a known bug and says a fix was scheduled for full deployment the week of July 17, 2026. Given rising phone-theft rates, the flaw raises the risk of an attacker sending convincing scam messages from a victim's number before they regain control of the device.

Severity: Medium (requires physical possession of an unlocked-screen-but-locked device, so it isn't remotely exploitable, but it defeats the PIN authentication guarding a security-sensitive action)

Steps to reproduce:

  1. On a locked Android 16 device with Gemini's lock-screen access enabled (even if Messages/WhatsApp access has been manually revoked), open Gemini from the lock screen.
  2. Attempt to send an SMS through Gemini; when it prompts for the PIN, press "Continue" and Gemini's "Add attachment" button at the same time.
  3. This simultaneous tap bypasses the PIN prompt, letting the SMS send unauthenticated.
  4. Typing @WhatsApp into Gemini's text field similarly re-enables WhatsApp access without a PIN.

Affected product: Android
Affected versions: Android 16 devices (Google says it's not Pixel-specific, though some Samsung users reported being unable to reproduce it)
First seen: May 2026

Workaround: Disable Gemini's lock-screen access entirely until the patch arrives
Fixed versions: Not yet available — Google said a full fix was scheduled for deployment the week of July 17, 2026, but it had not universally shipped as of the July 19, 2026 follow-up coverage

Sources:

0 Answers