Android Lock Screen Bug Lets Gemini Send SMS Without PIN – Fix Coming

A critical Android bug lets attackers send SMS via Gemini without a PIN. Google confirms a fix is rolling out this week. Learn how it works and protect

lunes, 27 de julio de 2026 • 4 min read • Q2BSTUDIO Team

Google corrige vulnerabilidad de Gemini en la pantalla de bloqueo

A security flaw has recently come to light in Android that allows an attacker with physical access to the device to send SMS or WhatsApp messages from the lock screen without needing to know the PIN. The vulnerability affects the integration of Gemini, Google's artificial intelligence assistant, and has been reported multiple times since May. Although Google has already announced a fix scheduled for this week, the incident highlights the importance of designing robust systems that combine the convenience of AI assistants with solid authentication protocols.

The bug manifests when a malicious user performs a specific multi-touch gesture on the lock screen while interacting with Gemini. Under normal conditions, if the phone owner has revoked Gemini's permission to access apps like Messages, attempting to send an SMS prompts the assistant to open the corresponding app and then request the PIN. However, by simultaneously pressing the 'Continue' button and Gemini's 'Add attachment' button, the system skips verification and allows the message to be sent without authentication. From there, the attacker can enable Gemini's access to other previously blocked apps, such as WhatsApp, simply by typing '@WhatsApp' in the text window. All without needing to enter the lock code.

From a business perspective, this type of vulnerability underscores the need for cybersecurity services that go beyond simple patching. Organizations that use corporate mobile devices or develop applications for the Android ecosystem must consider how integrating AI assistants can open unexpected attack vectors. At Q2BSTUDIO, as a software and technology development company, we work to help businesses anticipate these risks through custom software development that incorporates granular access controls from the design phase.

Artificial intelligence, and specifically AI agents like Gemini, are transforming how we interact with devices. However, their integration must be done carefully to avoid compromising security. A recommended approach is to implement additional authentication layers, such as biometrics or contextual verification, that do not rely solely on the PIN. Additionally, companies adopting cloud solutions must ensure their access policies extend to mobile devices as well. For example, using AWS or Azure cloud with identity and access management (IAM) services that can audit and control which applications are allowed to act on behalf of the user.

Phone theft is a growing problem, especially in countries like the UK, where criminals exploit these flaws to carry out fake kidnapping scams through convincing messages. In a corporate context, an attacker who gains physical access to an employee's device could compromise internal communications, access sensitive data, or even impersonate the employee to send fraudulent instructions to other team members. Therefore, cybersecurity must include policies for remote lock, end-to-end encryption, and continuous training on the risks associated with AI assistants.

Beyond the immediate patch, companies should consider developing customized software that integrates security mechanisms tailored to their workflow. For instance, a corporate messaging app could disable access from external assistants when the device is locked, or require multi-factor authentication for any sensitive action. At Q2BSTUDIO, we offer AI and intelligent agent solutions that can be configured to strictly adhere to security policies, preventing them from becoming a weak point.

Data analytics also plays a key role in early anomaly detection. With Business Intelligence tools like Power BI, companies can monitor mobile device usage patterns and alert on suspicious behavior, such as unauthorized attempts to access Gemini functions. Implementing a BI/Power BI system allows correlating security events and taking proactive measures before an incident materializes.

The Gemini vulnerability is not exclusive to Pixel devices; it affects multiple manufacturers and Android 16 versions. Google has not specified which models are vulnerable, creating uncertainty in the ecosystem. For companies managing device fleets, it is crucial to have an incident response plan and an update strategy that minimizes the exposure window. Process automation can help deploy patches quickly and consistently, an area where software automation from Q2BSTUDIO can make a difference.

In summary, although the Android lock screen flaw is serious, it also presents an opportunity to reflect on how we integrate artificial intelligence into our devices and enterprise systems. Security should not be an afterthought but a fundamental pillar from design. At Q2BSTUDIO, we help organizations build robust technological solutions, combining cybersecurity, cloud, BI, and AI coherently. If your company seeks to protect its data and ensure that its custom applications are secure against emerging threats, do not hesitate to contact us.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.