Android Lock Screen Flaw Lets Gemini Send Messages Without PIN

A gesture-based bypass in Android's lock screen allows unauthorized message sending through the Gemini assistant, undermining a core security boundary.

Abstract illustration depicting a security boundary with a breach
AI-generated illustration · Sylvaris

Authentication Bypass Through Multi-Touch

Google is addressing an Android lock screen vulnerability that allows anyone with physical access to a device to send SMS messages through Gemini without entering a PIN. The flaw involves a specific multi-touch gesture that bypasses the authentication prompt.

The vulnerability affects the integration between Android's lock screen security and the Gemini assistant. When triggered, the system fails to enforce the expected authentication step before executing sensitive actions.

Physical Access Required

The exploit requires direct physical interaction with a locked device, limiting the attack surface to scenarios where someone can handle the phone. This distinguishes it from remote vulnerabilities but still poses privacy and security risks in theft or social situations.

Lock screen bypasses typically carry lower severity ratings than remote exploits, yet they undermine the device's primary physical security mechanism.

Fix in Progress

Google has confirmed the issue and is working on a patch. No timeline for the fix has been disclosed. Until the update arrives, users concerned about physical device security should disable lock screen assistant access or limit Gemini's permissions.

sources
more in Security
Upbound breach enabled $13 million in fraudulent Acima leases Stolen customer data was directly weaponized to create fraudulent financial contracts, demonstrating how breach data enables immediate financial crime. Fake job interview delivers malware through Git hooks in take-home coding projects Attackers are weaponizing the technical interview process itself, embedding malicious Git hooks in legitimate-looking coding assignments to compromise developer workstations. South Korea National Diplomatic Academy breach exposes global diplomat data after ten-month intrusion A prolonged breach of diplomatic training infrastructure exposed sensitive personnel data of current and former foreign service officers worldwide, demonstrating the targeting of government educational systems.