11.3 C
Canberra
Tuesday, July 21, 2026

Google’s Gemini lets strangers ship messages out of your locked Android cellphone


Gemini, Google’s AI assistant, is meant to make life simpler for Android smartphone house owners. However proper now it could even be making life simpler for anybody anybody who occurs to choose up your cellphone.

As The Register stories, Google is engaged on a repair for a vulnerability that enables an attacker with bodily entry to a locked Android 16 gadget to make use of Gemini to ship SMS messages and WhatsApp texts, with out ever needing to enter a PIN.

So, think about the scene. Somebody will get maintain of your locked Android cellphone and, regardless of not understanding your safety PIN, they will ship messages through SMS or WhatsApp pretending to return from you.

The Register says that it has acquired a number of stories since Might of how it’s attainable to bypass authentication on Android 16 gadgets which have enabled Gemini entry from the lock display screen.

In Might 2026, a safety researcher printed a write-up describing how they’d reproduced the issue on a completely patched Pixel 6a, utilizing Gemini’s Deep Analysis characteristic because the entry level.

It’s clear that Google has patched Gemini lock display screen points earlier than, however safety researchers maintain discovering new methods by.

The most recent vulnerability is totally different from the earlier comparable Gemini-based Android lock display screen bypass bugs which were plaguing the working system since September 2025.

This newest exploit requires a selected multi-touch gesture. When Android gadgets have revoked Gemini’s entry to apps like Messages, and somebody tries to ship an SMS through Gemini on the lock display screen, the person is prompted to enter a PIN. Nevertheless, when “Proceed” is pressed concurrently with Gemini’s “Add attachment” button, the gadget permits the SMS to be despatched with none authentication.

An attacker can then allow Gemini’s entry to different beforehand disconnected apps. All they must do is invoke the related immediate by – as an example – typing “@WhatsApp” in Gemini’s textual content window. As soon as once more, no PIN is requested or required.

What makes this notably sneaky is that the modifications are usually not momentary. If a sufferer later unlocks their cellphone and checks their Gemini settings, they’ll discover that WhatsApp has been related to Gemini, despite the fact that no PIN was ever entered.

In fact, exploiting a vulnerability like this does require bodily entry to a susceptible Android gadget. This isn’t an assault which will be carried out by a distant hacker. However, as everyone knows, it’s all too frequent for a tool to be left unattended, or snatched from a bag, or handed to somebody you assume you’ll be able to belief.

A spokesperson at Google informed The Register that this new bug is understood about, and {that a} repair is scheduled to be rolled-out this week. However within the meantime, you’ll be clever to limit what Gemini can entry out of your lock display screen.

To try this:

  • Open the Gemini app, faucet your profile image, go to Settings, and choose “Gemini on lock display screen.”
  • Flip off “Use Gemini with out unlocking” totally, or (if you’re not snug with that) disable “Make calls and ship messages with out unlocking.”

Google will little question patch this explicit bug. However the underlying drawback remains to be current. Each new functionality Gemini is given on the lock display screen can be a brand new potential assault floor. The extra helpful your AI assistant turns into with out you needing to unlock your cellphone, the more durable it turns into to ensure that solely you should use it.

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

[td_block_social_counter facebook="tagdiv" twitter="tagdivofficial" youtube="tagdiv" style="style8 td-social-boxed td-social-font-icons" tdc_css="eyJhbGwiOnsibWFyZ2luLWJvdHRvbSI6IjM4IiwiZGlzcGxheSI6IiJ9LCJwb3J0cmFpdCI6eyJtYXJnaW4tYm90dG9tIjoiMzAiLCJkaXNwbGF5IjoiIn0sInBvcnRyYWl0X21heF93aWR0aCI6MTAxOCwicG9ydHJhaXRfbWluX3dpZHRoIjo3Njh9" custom_title="Stay Connected" block_template_id="td_block_template_8" f_header_font_family="712" f_header_font_transform="uppercase" f_header_font_weight="500" f_header_font_size="17" border_color="#dd3333"]
- Advertisement -spot_img

Latest Articles