Security researchers found a Gemini vulnerability that can bypass the Android lock screen. Someone with physical access to a phone may use the assistant to send an SMS without entering the PIN. Reports of the issue have circulated since May 2026, and Google says a fix has been prepared.
Under normal conditions, the protection works as expected. When Gemini is opened from the lock screen and asked to send a message, Android requests that the device be unlocked. Researchers found, however, that pressing “Add attachment” and “Continue” at the same time dismisses the verification prompt, after which Gemini sends the message.
The issue is not limited to SMS. The same sequence can reconnect WhatsApp to Gemini even after the device owner disabled the integration in settings. Calling WhatsApp through the assistant interface does not trigger another PIN check.
Exploitation requires physical access to the device. The issue was observed on phones running Android 16, but Google has not published a complete list of affected manufacturers, models or system versions. The company says the fix is ready and should be fully rolled out soon.
Until the update is installed, users are advised to disable Gemini on the lock screen. In the Gemini app, open “Settings” — “Gemini on lock screen” and turn off “Use Gemini without unlocking.” Calls and messages from a locked device can also be disabled separately.