Android Lock Screen Flaw Lets Gemini Send Messages Without PIN
A gesture-based bypass in Android's lock screen allows unauthorized message sending through the Gemini assistant, undermining a core security boundary.
Authentication Bypass Through Multi-Touch
Google is addressing an Android lock screen vulnerability that allows anyone with physical access to a device to send SMS messages through Gemini without entering a PIN. The flaw involves a specific multi-touch gesture that bypasses the authentication prompt.
The vulnerability affects the integration between Android's lock screen security and the Gemini assistant. When triggered, the system fails to enforce the expected authentication step before executing sensitive actions.
Physical Access Required
The exploit requires direct physical interaction with a locked device, limiting the attack surface to scenarios where someone can handle the phone. This distinguishes it from remote vulnerabilities but still poses privacy and security risks in theft or social situations.
Lock screen bypasses typically carry lower severity ratings than remote exploits, yet they undermine the device's primary physical security mechanism.
Fix in Progress
Google has confirmed the issue and is working on a patch. No timeline for the fix has been disclosed. Until the update arrives, users concerned about physical device security should disable lock screen assistant access or limit Gemini's permissions.