Artificial Intelligence

Your Android PIN Won’t Stop This Gemini Lock Screen Trick

Published

on

Your phone’s lock screen is supposed to be a wall. This Gemini bug just kicked a hole in it.

Since May, researchers have been quietly reporting the same troubling scenario to The Register: someone grabs your Android phone, taps the lock screen, and starts sending texts through Google Gemini — no PIN, no fingerprint, nothing. The flaw affects Android 16 devices where Gemini can be summoned directly from the lock screen.

It’s a narrow exploit, sure. But it’s nasty enough that Google has already confirmed a fix is on the way. In fact, the company says the full patch is scheduled to roll out this week.

How the Gemini lock screen bug works

The trick hinges on a specific, awkward timing move. Normally, if you’ve revoked Gemini’s access to Messages, asking it to send a text from the lock screen forces you to open the app — and that’s where your PIN gets checked. But there’s a loophole.

Press Continue at the exact same moment Gemini’s Add Attachment button appears, and the authentication check simply never fires. The SMS goes through as if you’d unlocked the phone yourself.

It gets worse from there. Typing @WhatsApp into Gemini’s text field can silently reconnect apps you had previously disconnected — again, no PIN required. Afterward, checking your settings would show WhatsApp linked to Gemini as if you’d approved it with your own thumb.

The exact sequence that breaks the PIN check

  • Open Gemini from the lock screen and ask it to send a message.
  • When prompted, tap Continue and Add Attachment simultaneously.
  • The app proceeds without authentication — SMS and even WhatsApp messages go out.

It’s a race-condition flaw, the kind that’s notoriously hard to patch perfectly. But Google says the fix is already being deployed.

How risky is this exploit really?

Let’s be clear: this isn’t a remote attack. Someone needs physical access to your phone to pull it off. That makes it less terrifying than, say, a zero-click exploit from a malicious website.

Still, researchers warn it’s a real problem for phone theft. A thief who grabs your unlocked — or even locked — device could fire off convincing messages to your contacts before you ever get a chance to lock it down remotely. Imagine your mom getting a text that sounds exactly like you, asking for money, sent from your actual number.

And it’s not just Pixel devices. Some users say they couldn’t reproduce the bug on Samsung phones, but Google hasn’t clarified which manufacturers or models remain vulnerable. That ambiguity is its own kind of risk.

What should you do right now?

Until the patch lands on your phone, the safest move is simple: turn off Gemini’s lock screen access entirely.

Here’s how to do it on most Android 16 devices:

  1. Open the Google app.
  2. Tap your profile picture and go to Settings.
  3. Select Gemini.
  4. Toggle off Lock screen access.

That kills the attack vector completely. You’ll lose the convenience of asking Gemini questions without unlocking, but honestly — that’s a trade worth making for the next few days.

If you’re curious about broader lock screen protections, check out our guide on Android lock screen security settings to see what else you might be missing. And for more on how Google handles these disclosures, read about Google’s Android security update process.

The bottom line

This bug is a reminder that your lock screen is only as strong as the code behind it. A single timing flaw can undo the whole thing. Google has acknowledged the issue and says the fix is rolling out this week — but until you see that update notification, keep Gemini off your lock screen.

It’s a small inconvenience for a big peace of mind. And honestly, do you really need Gemini to answer questions while your phone is still in your pocket?

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version