Google is working to address a newly disclosed security vulnerability affecting its Gemini AI assistant that could allow someone with physical access to a locked Android 16 device to send SMS and WhatsApp messages without entering the device PIN. According to a report by The Register, the flaw enables attackers to bypass authentication under specific conditions, allowing them to send messages that appear to come from the device owner. The issue has raised concerns because Gemini is designed to provide convenient access from the lock screen, but the same functionality can also create opportunities for unauthorized actions if security controls are bypassed. Google has acknowledged the vulnerability and confirmed that a software fix is scheduled to be released this week.
The Register reported receiving multiple disclosures about the issue since May, when researchers demonstrated that authentication could be bypassed on Android 16 devices with Gemini enabled on the lock screen. A security researcher also published technical findings in May 2026 after successfully reproducing the vulnerability on a fully updated Pixel 6a using Gemini’s Deep Research feature as the entry point. Although Google has previously resolved several Gemini related lock screen security issues, researchers continue to identify new methods of bypassing authentication. Unlike earlier vulnerabilities reported since September 2025, this latest issue relies on a specific multi touch interaction. When Gemini has been prevented from accessing applications such as Messages, users attempting to send an SMS from the lock screen are normally prompted to enter a PIN. However, researchers found that pressing the “Continue” button at the same time as Gemini’s “Add attachment” button allows the message to be sent without any authentication, effectively bypassing the intended security protection.
Researchers also found that the same technique can be used to reconnect Gemini with applications that had previously been disconnected. By entering prompts such as “@WhatsApp” into Gemini, an attacker can enable access to additional applications without entering the device PIN. Even more concerning, these permission changes remain active after the legitimate owner unlocks the phone. When reviewing Gemini settings later, users may discover that applications such as WhatsApp have been connected even though no authentication was performed. While the vulnerability requires physical possession of the device and cannot be exploited remotely, security experts note that smartphones are frequently left unattended, temporarily handed to other people, or stolen, creating situations where attackers could take advantage of the flaw. This makes the issue particularly relevant for users who rely on lock screen features for convenience while assuming their messages remain protected by device authentication.
Google confirmed to The Register that it is aware of the vulnerability and has already prepared a fix that is expected to roll out during the week. Until the update is installed, users are advised to limit what Gemini can do from the lock screen. This can be done by opening the Gemini application, selecting the profile picture, navigating to Settings, and accessing the “Gemini on lock screen” options. Users can either disable “Use Gemini without unlocking” completely or turn off the option allowing Gemini to make calls and send messages without unlocking the device. Although the upcoming update is expected to resolve this specific issue, researchers note that every new capability added to AI assistants on the lock screen also increases the potential attack surface. As AI features become more integrated into everyday smartphone use, maintaining a balance between convenience and security will remain an important consideration for both technology providers and users.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.