MilikMilik

Gemini’s Lock Screen Bug Turns Your Phone Into an Open Messenger

Gemini’s Lock Screen Bug Turns Your Phone Into an Open Messenger
Interest|Mastering Your Phone

A lockscreen flaw that turns Gemini into a free messaging pass

The Gemini SMS bypass is an Android lockscreen security flaw where a specific multi‑touch gesture lets anyone with physical access send SMS or WhatsApp messages through Gemini without entering the device’s PIN, exposing users to impersonation and social‑engineering risks even when their phone appears securely locked.

The uncomfortable truth: if someone gets hold of your Android phone, they can use Gemini from the lockscreen to send messages as you, despite not knowing your PIN. This is not theoretical. Reports since May describe an authentication bypass on Android 16 devices that allow Gemini on the lockscreen, letting attackers step around the very barrier that should protect your identity. In security terms, this is a textbook lockscreen bypass vulnerability, born from the collision of complex AI features with special system privileges. The incident underlines a hard lesson: when we invite assistants into the lockscreen, we expand the attack surface of our most personal device, and bugs in that layer matter far more than cosmetic glitches.

How the multi‑touch Gemini SMS bypass works

Stripped to its essentials, the exploit is both simple and unsettling. When owners have deliberately revoked Gemini’s access to apps like Messages, attempts to send an SMS from the lockscreen should trigger a prompt to open the app and a demand for the correct PIN. That part works—until human fingers do something the software designers did not anticipate.

One reported bug lets an unauthenticated person enable phone, texts, and WhatsApp via Gemini on the lockscreen with a specific multi‑touch gesture. The key move is pressing the “Continue” button, which should enforce PIN entry, at the exact same time as Gemini’s “Add attachment” button. When these actions coincide, the device allows the SMS to be sent via Gemini without any PIN at all, a clear Android PIN bypass. From there, the attacker can re‑enable Gemini’s access to other apps, like WhatsApp, simply by invoking the right prompts inside Gemini, again without authentication. A single mis‑handled gesture unravels the intended security model.

Who is affected and how serious is this phone security vulnerability?

This is not limited to one model or a niche beta build. Reports since May describe device authentication being bypassed on Android 16 devices that allow Gemini from the lockscreen. Google has confirmed that the bug is known and not specific to its own phones, even though some users say they cannot reproduce it on certain other brands. We still do not know the exact list of manufacturers, models, or Android variants that are vulnerable, which leaves a frustrating uncertainty hanging over many users.

Technically, the severity is limited by one important condition: exploiting the flaw requires physical access to the device. On paper, that might sound minor. In practice, that view is naive. Modern phone theft is organized and opportunistic, and the ability to send convincing SMS or WhatsApp messages as the victim opens doors to high‑impact scams, including fake kidnapping messages and other social‑engineering attacks. The combination of theft plus instant impersonation is exactly the kind of real‑world scenario where lockscreen bypass bugs stop being curiosities and become genuine threats to everyday users.

Google’s incoming fix does not erase the lesson on lockscreen security

There is some good news: Google says this is a known bug, a fix has already been implemented, and a full deployment was scheduled for this week. In other words, this is not being ignored in a backlog somewhere; the company is pushing out a patch to close the Gemini SMS bypass. The vulnerability has been on its radar since at least May, which explains the relatively fast response now that public attention has caught up.

But focusing only on the fix misses the deeper issue. These are not the first Gemini‑based Android lockscreen bypass bugs that have surfaced; similar issues have been reported since 2025. Each time we give AI assistants special lockscreen privileges, we create new edge cases where complex interactions—like overlapping buttons or attachment workflows—can short‑circuit intended protections. The pattern is clear: Android lockscreen security is only as strong as the weakest privileged feature allowed to run before you type your PIN. That means any future integration at the lockscreen should be treated as a potential vulnerability, not a convenience upgrade, until it proves otherwise.

Milik earns a commission when you shop through our links, at no extra cost to you. Editorial content is independently selected by our team.

You May Also Like

Comments
Say something...
No comments yet. Be the first to share your thoughts!