Gemini is Allowing Attackers to Bypass the Android Lock Screen

Gemini is Allowing Attackers to Bypass the Android Lock Screen

The Register received multiple reports of people being able to access features such as sending SMS or WhatsApp messages from the lock screen when Gemini is enabled.

Gemini is Google's AI assistant that can perform actions inside Android apps on your behalf.

One bug that was reported allows an unauthenticated user with physical access to an Android device to perform certain actions on the lock screen such as sending SMS and WhatsApp messages even when Gemini access to those apps was revoked.

When Gemini is active on the lock screen, an attacker can attempt to send an SMS from Gemini, at which point it will ask you if you want to open the relevant app with a "Continue" button. If you press continue, you'll be presented with a screen to enter your PIN to unlock the app.

However, if you press Gemini's "Add attachment" button down while pressing "Continue" at the same time, it will bypass the PIN and allow you to send an SMS through Gemini.

This also opens the door for access to other apps. The attacker can now access other apps which were explicitly disallowed from being accessed by Gemini simply by invoking the relevant prompt.

For example, you can access WhatsApp through Gemini by entering "@WhatsApp" in the text window with no PIN needed at all.

You can unlock your phone properly and check in the settings, and you'll see that WhatsApp is now connected to Gemini without any authentication.

A Google spokesperson told The Register that it is a known bug and a fix is incoming this week, and that the bug is not specific to Pixels.

Another Gemini lock screen bypass utilizes the "Deep Research" feature. According to the writeup from the security researcher who discovered it:

An attacker with brief physical access to a locked Android device can without ever entering a PIN, pattern, or biometric switch Google accounts, modify security settings, read and exfiltrate Gemini conversation history, and set up persistent lock screen messaging and calling capabilities.

Despite Google claiming to have patched it all the way back in 2024, the researcher says it remains unpatched in 2026 due to the original patch not covering the full breadth of the issue.

In general, it's best to keep features accessible in the lock screen to an absolute minimum as anything you enable is more attack surface that could lead an exploit.

Community Discussion