DilmipaintCorrespondents · Reports · Analysis
CORRESPONDENT REPORTAI & ML

Security Flaw in Google’s Gemini Lets Unauthorized Users Send Messages from Locked Devices

Published
Jul 17, 2026
Desk
AI & ML
Views
938

A vulnerability in Google’s Gemini AI allows unauthorized access for message-sending from locked Android devices. Users should review app permissions now.

Google's Gemini AI assistant was designed to enhance the functionality of Android smartphones, but a recently discovered vulnerability raises serious concerns about its security. An issue allows anyone with physical access to a locked Android 16 device to exploit Gemini to send messages via SMS or WhatsApp, bypassing the need for a PIN. This kind of security flaw, especially in devices we depend on daily, is not just a minor inconvenience; it's a potential gateway for malicious activities.

Identifying the Vulnerability

Reports of this security lapse began surfacing in May, with several independent observers noting how the lock screen functionality of Gemini could be manipulated to send messages without authentication. According to The Register, these accounts documented a serious flaw where an attacker could access your device and impersonate you in text communications. This isn’t just a case of a slick trick—it's a fundamental issue that compromises user privacy and data security.

A security expert first detailed the issue in a write-up last May, demonstrating how the Deep Research feature in Gemini could act as a backdoor. They successfully reproduced the problem on a fully updated Pixel 6a, highlighting the sophistication of this exploit rather than it being just another bug. The fact that it took a dedicated expert to expose this flaw emphasizes the inadequate safeguards that exist in consumer technology, raising questions about how many such vulnerabilities remain undiscovered.

Exploiting a System Flaw

This vulnerability represents a notable shift from previous issues that allowed bypassing of the lock screen using Gemini. All of them reveal an unsettling trend of security researchers uncovering new methods to exploit Gemini's access. The latest bug leverages a specific multi-touch gesture, which contradicts the typical security intentions behind the lock screen. Users often assume that locking their devices will protect them from unauthorized use, but this flaw shines a light on a disturbing contradiction in user protections.

Here’s how it works: when Gemini's access is revoked for apps like Messages, any attempt to send a text usually prompts for a PIN. However, performing a simultaneous touch on the "Continue" button alongside the "Add attachment" button allows messages to slip through the cracks of authentication. This kind of exploitation—taking advantage of behavior that users would never expect—makes it increasingly difficult for regular users to recognize and protect themselves from security risks.

The Broader Implications

The implications are serious. An attacker can not only send messages but also restore access to other disconnected applications. By merely entering a command like "@WhatsApp" in Gemini’s interface, they can establish a connection, surprising the user later when they discover their permissions have been altered after unlocking their device. (And this is the part most people overlook—it shifts the responsibility, placing security back on users instead of the developers.)

What's particularly alarming is that these changes are persistent. Even after a user unlocks the phone, their Gemini settings will show new accesses made without their knowledge or consent. This highlights a fundamental challenge: while offering convenience, new features in AI assistants like Gemini also expand the surfaces available for potential exploitation. Every layer of complexity adds a potential avenue for attackers to penetrate, making the task of safeguarding user data exponentially more difficult.

The Real-World Risk

While it’s true that exploiting this vulnerability demands physical access—thus limiting remote attacks—the risk is nonetheless real. People frequently leave their devices unattended, trust friends with them, or inadvertently place them in unsecured environments. A misplaced smartphone can quickly become a conduit for privacy violations, likening the risk to leaving your front door unlocked. A moment of carelessness can have ongoing consequences.

Google's Response and Recommendations

A representative from Google confirmed that the company is aware of the flaw and plans to implement a fix soon. In the meantime, users are advised to take immediate steps to tighten their controls over what Gemini can access from the lock screen. This includes:

  • Accessing the Gemini app, tapping your profile picture, navigating to Settings, and selecting "Gemini on lock screen."
  • Disabling “Use Gemini without unlocking” or at least turning off the option to “Make calls and send messages without unlocking.”

The irony here is stark: as we embrace powerful features that AI assistants offer, we're also unintentionally exposing ourselves to new risks. While Google is likely to patch this vulnerability, it underscores a continuing issue with AI assistants. Each new feature introduced at the lock screen introduces further opportunities for misuse. The challenge lies in balancing usability with stringent security, a task that will require ongoing vigilance as capabilities expand.

Looking Ahead: Security and Functionality

What this means for you—if you're working in this space or simply a consumer—is that there needs to be an acknowledgment of the trade-offs inherent in technology. The arms race between developers aiming to create more intuitive, responsive technologies and those seeking to exploit their vulnerabilities might only escalate. Users must be proactive, taking the time to understand and manage the settings and functionalities of their devices. Failure to do so could lead to serious security breaches.

As devices become smarter and more interconnected, the push for security must match the pace of innovation. Otherwise, we might find ourselves in a position where convenience comes at too high a cost.

Source: Graham Cluley · www.bitdefender.com

Discussion

Sign in to join the discussion.