Android lockscreen bypass allows Gemini to send SMS without verification

A security vulnerability in Android allows users to bypass the lock screen to send SMS messages and re-enable app permissions via Gemini. Google is reportedly aware of the issue and is working on a fix for the affected devices.
Why it matters
This highlights critical security risks associated with AI assistants having deep system-level privileges on mobile devices.
These things happen from time to time, especially when dealing with such complex software with so many edge cases and even more so with software with special privileges like Gemini’s ability to run from the lock screen.
In traditional “hacking” circles, this is known as an authentication bypass vulnerability or a lockscreen bypass. It is always so fascinating to observe what things people find or often stumble upon. You can see the short video for yourself. Still, it goes something like this: The user has mindfully disabled access from Gemini to certain apps like Messages, so naturally, once someone with physical access to the device tries to call upon Gemini from the lock screen and tell it to send a message, the phone asks for a PIN. So far so good.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in