Gemini Lock-Screen Flaw Raises Fresh Questions Over AI Access to Private Messaging Apps
Google is preparing a broader fix for an Android security flaw that could allow someone with physical access to a locked phone to use Gemini to send messages through SMS or WhatsApp without entering the device PIN.
The issue, reported on Android 16 devices where Gemini is allowed to operate from the lock screen, has renewed concerns over how deeply artificial intelligence assistants should be integrated into private communication tools.
Unlike a remote cyberattack, the reported method requires the attacker to have the phone in hand. However, security researchers say the vulnerability could still allow unauthorized messages to be sent in the owner’s name, potentially creating risks ranging from impersonation and fraud to reputational damage.
Authentication safeguard reportedly bypassed
Under normal conditions, Gemini should require the user to unlock the phone before accessing messaging applications when permission has been restricted.
Reports suggest that a particular multi-touch sequence can interfere with that authentication step. Once the prompt is bypassed, Gemini may process a request to send an SMS without requiring the expected PIN verification.
The weakness is being described as an authentication bypass because it does not crack the phone’s PIN. Instead, it allegedly enables an action that should remain protected until the device has been properly unlocked.
WhatsApp permissions may be restored without consent
The reported impact extends beyond text messages.
Security researchers say the same flaw could allow Gemini to regain access to applications that had previously been disconnected from the assistant, including WhatsApp. Once the connection is restored, the assistant may be used to send messages from the locked device.
More concerningly, the change may remain active after the phone is unlocked. Researchers reportedly found that affected apps could appear connected to Gemini in the phone’s settings even though the user had not entered the PIN during the lock-screen interaction.
This means the issue may not simply involve a one-time message. It could also alter the user’s app permissions without clear authorization.
Broader concern beyond Pixel devices
The vulnerability was reproduced on a fully updated Pixel 6a, but Google has reportedly said the problem is not limited to Pixel smartphones.
The company has not yet published a complete list of affected brands, models, or software versions, leaving the full scale of the issue uncertain.
The reported flaw is also separate from earlier Gemini-related lock-screen bypasses that emerged in 2025, suggesting that the growing role of AI assistants in Android may continue to create new security challenges.
The incident highlights a wider problem facing smartphone manufacturers.
AI assistants are increasingly being designed to perform tasks without requiring users to unlock their devices. This makes them faster and more convenient, particularly for actions such as setting reminders, making calls, or sending messages.
But the same convenience can weaken security if the assistant is allowed to interact with sensitive apps before the phone verifies the user’s identity.
Messaging applications are especially sensitive because a message sent from a person’s phone is often treated as genuine by friends, relatives, colleagues, and financial contacts.
An attacker using a locked device could potentially send misleading instructions, request money, impersonate the owner or create confusion before the real user becomes aware of the activity.
Google has acknowledged the issue and says a fix has already been developed.
The update was expected to receive wider deployment during the week, though the company has not provided full technical details about the vulnerability or confirmed whether every affected device will receive the patch at the same time.
Until the update reaches users, Android owners who allow Gemini to operate from the lock screen may want to review the assistant’s permissions, particularly its access to WhatsApp, Messages, and other communication apps.
Users should also install Android system and Google app updates as soon as they become available.
The flaw serves as another reminder that AI features must be judged not only by what they can do but also by what they should be allowed to do before a device is unlocked.
Also read:
First Look: Google’s Gemini App Redesign Is Bold, Beautiful, and Very Different
Mobile Phone Taxes Portal
Find the PTA Taxes on All Phones on a Single Page using our Taxes Portal.
Note: Mobile phone tax rates and calculations fall under the jurisdiction of the Federal Board of Revenue (FBR), not the Pakistan Telecommunication Authority (PTA).