A new Android security threat has sparked concerns about lock screen security after researchers were able to bypass authentication and make use of Gemini to send SMS messages without providing a PIN.The flaw, which apparently has been known by Google since May, impacts devices running Android 16 where the feature of Gemini is set up on the lock screen. Although the flaw needs the attacker to have physical access to the device, experts warn that the security flaw can help the attacker to send text messages and even re-connect WhatsApp apps to Gemini without any authentication process.About The AuthorJournalist and a writer with a strong interest in news, culture, technology, and human-interest stories. Passionate about making complex topics accessible and engaging.Google is aware of the security problem and is planning a patch for it.A lock screen bypass involving GeminiThe vulnerability falls into what's commonly known as an authentication bypass or lock screen bypass, a type of flaw that allows someone to access functions normally protected by a device's lock screen.According to reports, the issue appears when Gemini is available from the lock screen. If a user has previously disabled Gemini's access to apps like Messages, the AI assistant correctly asks for device authentication before carrying out actions such as sending an SMS.However, researchers discovered that the verification process can reportedly be bypassed using a specific multi-touch gesture.An attacker does not need to enter the necessary PIN, but rather needs to press Gemini’s “Continue” and “Add Attachment” buttons nearly simultaneously. This apparently enables bypassing the authentication screen and proceeding with the requested action.More than just sending SMSThis problem seems not to be restricted solely to text messages.More articles by AuthorTrending StoriesIt has been reported that when the bypass is initiated, Gemini may also gain access to applications which the users have disconnected.One example mentioned in the report involves WhatsApp. By typing "@WhatsApp" into Gemini after performing the bypass, the assistant reportedly reconnects the app without asking for the device PIN.Users can later verify that the app has been re-enabled by checking Gemini's settings after unlocking the device.This means someone with temporary physical access to a compatible phone could potentially restore permissions the owner had intentionally revoked.Not limited to Pixel phonesDespite being strongly linked with Google's Pixel range of phones, the problem does not seem to affect just these devices.As per the reports, the problem affects Android 16 devices supporting Gemini on their lock screen. The thing that still remains unknown is whether all the manufacturers have been affected by it.So far, no complete list of the devices affected has been issued by Google.Google says a fix is already rolling outFor users, the silver lining in this case is that Google is aware of the bug.Google spokespersons have apparently confirmed that Google is aware of the issue and has readied the software patch for fixing the same. It is expected that the roll-out will start this week.It is alleged that the vulnerability had been investigated since May due to repeated reports by users.Physical access is still requiredAlthough the vulnerability is quite serious, there is one major disadvantage of this attack – it cannot be performed remotely.One will have to gain physical access to the unlocked or even locked Android phone, in which Gemini application is present on the lock screen.While that reduces the overall risk compared to remote attacks, security experts note that lock screen protections exist precisely to prevent unauthorized actions when a phone falls into someone else's hands.Authentication bypass vulnerabilities like this occasionally surface on both Android and iOS, particularly as mobile operating systems become more complex and integrate AI assistants with deeper system privileges.Until Google's fix reaches all eligible devices, users who rely heavily on Gemini's lock screen features may want to keep an eye out for the upcoming software update. FAQsWhat is the Android Gemini lock screen bug?The bug apparently enables anyone who physically gets access to the Android version 16 to skip the lock screen authentication screen and use Gemini to send texts via SMS without using the device PIN.Is the bug limited to Pixel phones?No. It appears the problem isn’t limited to Pixel phones; however, Google hasn’t specified which Android phones have the vulnerability yet.Is the vulnerability exploitable from afar?No. The vulnerability can’t be exploited remotely.Has Google patched the vulnerability?Yes. Google has officially acknowledged the vulnerability and stated that a patch will soon be available on affected devices.end of article