A serious security vulnerability has been discovered in the Android ecosystem, affecting the latest version of the operating system — Android 16. The issue concerns the integration of the Gemini AI, which, as it turns out, can be exploited by attackers to bypass the lock screen and send messages on behalf of the device owner, even without knowing the PIN code.
How the lock screen bypass works
The essence of the vulnerability lies in the specific interaction between the interface and the AI assistant. If an attacker gains physical access to a locked smartphone, they can activate Gemini using a specific multi-sensor gesture command directly on the lock screen. This grants access to functions that should be protected, such as telephony, SMS sending, and messengers, including WhatsApp.
The scenario is particularly dangerous when a user attempts to restrict Gemini's permissions by blocking access to certain applications, such as "Google Messages." In the case of an attempt to send an SMS via the chatbot, the system correctly prompts to open the app and enter the PIN code. However, a logic error lies here: if the "Continue" button is pressed simultaneously with the "Add Attachment" button in the Gemini interface, the message is sent, completely ignoring the password entry requirement.
Access to WhatsApp and other services
The bypass mechanism is not limited to SMS only. An attacker can gain access to other applications, access to which was denied to the AI assistant, using specific requests. For example, to open WhatsApp, it is sufficient to enter the command "@WhatsApp" in the Gemini field. In this case, the system also skips the PIN entry stage, providing full access to the correspondence.
Scale of the problem and Google's response
Google has already confirmed the existence of this bug and promised to release a fix as part of an update coming this week. The company clarified that this lock screen bypass method does not work on Pixel devices. There have also been reports that the error does not reproduce on Samsung smartphones, however, the full list of manufacturers whose products are vulnerable to this flaw is not disclosed.
Experts note that physical access to the device is required to execute the attack, which may be difficult in real-world scenarios. Nevertheless, the ability to send messages on behalf of the victim using their phone number represents a real threat that cannot be underestimated.