Android Bug Lets Gemini Send Messages Without PIN
A newly discovered Android security flaw has raised concerns after researchers found that Google’s Gemini AI assistant can be tricked into sending SMS and WhatsApp messages from a locked device without requiring the user’s PIN.
According to a report by The Register, Google has acknowledged the issue and confirmed that a software update to fix the vulnerability will be released later this week.
How the Android Lock Screen Vulnerability Works
The exploit requires someone to have physical access to an Android phone. By performing a specific multi-touch action, an attacker can bypass the normal lock screen protection.
The method involves pressing Gemini’s “Add attachment” button and the “Continue” prompt at the same time when the AI requests permission to access apps such as Google Messages. This unexpected behavior allows Gemini to send SMS messages even though the device remains locked.
Researchers also found that the same technique can be used with WhatsApp. By entering “@WhatsApp” inside the Gemini chat window, an attacker can instruct the AI assistant to send messages without unlocking the phone or entering the device PIN.
Why the Security Issue Matters
Although the vulnerability requires physical access to the phone, security experts warn that it still poses a serious risk. A stolen or unattended device could be misused to send fraudulent messages, impersonate the owner, or support scams such as fake emergency or kidnapping schemes.
Google has clarified that the issue is not limited to Pixel smartphones and may affect Android devices running Gemini across different manufacturers.
Google Preparing Security Update
Google says it has already developed a fix and plans to roll it out through a software update this week. Users are advised to install the latest security updates as soon as they become available to protect their devices.
Until the patch is released, Android users should avoid leaving their phones unattended and keep their devices physically secure to reduce the risk of unauthorized access.
