Google Fixing Android 16 Gemini Lock Screen Bug on Android 16

Google Fixing Android 16 Gemini Lock Screen Bug on Android 16

Google is rolling out a security fix for an Android 16 vulnerability that could allow unauthorized users to send WhatsApp or SMS messages through Gemini from a locked phone without entering the device PIN.

The issue affects Android 16 devices where Gemini is enabled for lock screen access. Although the exploit requires someone to have physical possession of the phone, security researchers say it could still be used to impersonate the device owner by sending messages without completing the normal authentication process.

Authentication Bypass Raises Security Concerns

Cybersecurity experts have described the flaw as an authentication bypass because it allows Gemini to perform actions that should normally require the phone to be unlocked.

According to reports from The Register, the vulnerability appears when Gemini’s access to messaging applications has been disabled by the user. Under normal circumstances, Gemini should request the device PIN before sending messages from the lock screen.

However, researchers found that a specific multi-touch interaction could bypass that security check, allowing SMS messages to be sent without unlocking the phone.

WhatsApp Could Also Be Affected

The vulnerability reportedly extends beyond Google’s Messages app.

Security researchers found that the same flaw could restore Gemini’s access to previously disconnected applications, including WhatsApp. Once access is re-enabled, Gemini may be able to send WhatsApp messages directly from the lock screen without requiring PIN verification.

Researchers at Bitdefender also reported that the restored permissions may remain active even after the device is unlocked, indicating that the authorization change is not always temporary.

Security Researchers Reported the Issue Months Ago

The vulnerability has reportedly been known since May.

The Register said it received multiple reports involving Android 16 devices with Gemini enabled on the lock screen. Bitdefender also referenced research demonstrating the flaw on a fully updated Pixel 6a earlier this year.

The newly reported issue is separate from earlier Gemini-related lock screen vulnerabilities that have surfaced since 2025.

Bug Is Not Limited to Pixel Devices

Google has confirmed that the vulnerability is not exclusive to Pixel smartphones, suggesting that other Android manufacturers using Android 16 and Gemini lock screen features could also be affected.

The company has not yet published a complete list of impacted devices or manufacturers, leaving the full scope of the issue unclear.

Google Rolling Out a Security Update

Google said it has already developed a fix for the vulnerability and began rolling it out to users this week.

Until the update reaches all eligible devices, security experts recommend limiting Gemini’s lock screen capabilities if they are not required, as AI-powered lock screen features can introduce new attack surfaces when they interact with messaging applications and other sensitive services.

The incident highlights the growing security challenges surrounding artificial intelligence features integrated into smartphones, where convenience must be carefully balanced with user privacy and device protection.

Leave a Reply

Your email address will not be published. Required fields are marked *