Google is working on a fix for an Android lock screen bug that could let hackers break into WhatsApp or other messaging apps using Gemini from a locked phone without entering the device PIN.
The issue affects Android 16 devices that allow Gemini to run from the lock screen. The attack requires physical access to the phone, but reports say it can still allow someone to send SMS or WhatsApp messages as the device owner.
The bug is being described as an authentication bypass or lock screen bypass.
According to The Register, the issue appears when a user has disabled Gemini’s access to apps such as Messages. In normal use, Gemini should ask for the phone’s PIN before carrying out a locked-screen message request.
However, reports say a specific multi-touch interaction can bypass that authentication prompt. After that, Gemini can send an SMS without requiring the PIN.
The problem is not limited to SMS.
The same issue could allow Gemini access to be re-enabled for apps that the user had previously disconnected, including WhatsApp. Once enabled, Gemini could be used to send WhatsApp messages from the locked device without completing the expected authentication step.
Bitdefender also reported that this access is not only temporary. After unlocking the phone and checking Gemini settings, the affected app may appear connected to Gemini even though the PIN was never entered during the lock screen interaction.
The issue has reportedly been known since May.
The Register said it had received multiple reports of authentication bypasses on Android 16 devices with Gemini enabled on the lock screen. Bitdefender also noted that a security researcher published a write-up in May after reproducing the issue on a fully patched Pixel 6a.
The latest bug is separate from earlier Gemini-based Android lock screen bypass issues that have been reported since September 2025.
The vulnerability does not appear to be limited to Google Pixel phones.
Google told The Register that the bug is not Pixel-specific, although it did not provide a full list of affected manufacturers, models, or Android versions.
That means the full scope remains unclear for now.
A Google spokesperson told The Register that the company knows about the bug and has already implemented a fix.
The fix was scheduled for wider deployment this week. Until users receive the update, the issue remains a reminder that lock screen AI features can create new security risks when they are allowed to access messages or other apps without unlocking the device.
Similar lock screen bypasses have appeared on other platforms as well, including iOS, where researchers and online communities often look for edge-case ways to access restricted functions on locked devices.
For Android users, the main concern is clear: Gemini’s lock screen convenience should not come at the cost of bypassing basic phone authentication.
Get the latest tech news, telecom insights, and product launches wherever you prefer.
Add ProPakistani to Preferred Sources and see more of our stories in Google Search and Top Stories.