Google is racing to fix an Android flaw that lets anyone holding your locked phone text people as you, no PIN required. The bug runs through Gemini, the phone’s built-in AI assistant, and needs nothing more than physical access and a two-finger trick that takes about three seconds.
Google confirmed the flaw this week and says a patch is rolling out now. It is also the third confirmed break in the same feature since Google began letting Gemini act on a locked phone at all, a run that stretches back to September 2025.
Two Fingers, One Screen, No PIN
The mechanics are almost absurdly simple. On an Android 16 phone with Gemini enabled on the lock screen, asking the assistant to send a text normally triggers a PIN prompt if the owner has revoked Gemini’s access to the Messages app. Asking the assistant to send a text from the lock screen triggers a prompt requiring the correct PIN before anything can go through, at least in theory.
The theory breaks the moment two fingers hit the screen at once. The bypass happens when two on-screen actions are performed at nearly the same time: pressing Continue while simultaneously tapping Gemini’s Add attachment button skips that authentication check entirely, letting the SMS send without a PIN ever being requested. Some reports describe a slightly different trigger, a dedicated multi-touch gesture rather than the button-tap combination, suggesting more than one path into the same hole.
The WhatsApp Reconnection Trick
Once the first message goes out, the exploit does not stop there. Typing a command like “@WhatsApp” into Gemini’s text field can silently re-link an app the phone’s owner had specifically disconnected from Gemini, again without requiring a PIN, password, or biometric check of any kind.
Checking a device’s settings afterward would show WhatsApp reconnected to Gemini as though the owner had approved it themselves, even though the required authentication step never actually happened, which makes the bug more serious than a single unauthorized message since it can quietly undo deliberate privacy choices without leaving an obvious trace. Bitdefender, the antivirus and security firm that flagged the flaw publicly, found the change sticks around. Researchers at Bitdefender reported that the restored permissions may remain active even after the device is unlocked, indicating that the authorization change is not always temporary. WhatsApp itself is already drawing separate attention over user consent this year, with Indian regulators ordering Meta to pause its new username feature on privacy grounds, an unrelated case but a reminder of how often the app sits at the center of permission disputes right now.
Phone Theft Gives the Bug a Motive
Security researchers routinely wave off flaws that need physical access, on the logic that a stranger holding your unlocked hardware already has bigger problems to worry about than software. The Register, the UK technology and security outlet that first reported this bug, made exactly that point before rejecting it for this case.
the potential to send convincing SMS messages as part of fake kidnapping scams
The Register raised that scenario directly, tying the bug to what it called the state of phone theft crime, especially in the UK. Virtual kidnapping scams do not require an actual kidnapping. The Federal Bureau of Investigation (FBI) describes a version where a caller claims to be holding a relative and demands payment before the target can check whether the story is even true. On average, the family sends thousands of dollars to the scammers before contacting law enforcement. A convincing text sent from the real victim’s own number and WhatsApp account, by an attacker who never had to prove they knew a PIN, gives that script a new opening line.
None of this requires a remote hacker. The exploit requires physical possession of an unlocked-adjacent device, so it is most relevant to scenarios involving lost, stolen, or briefly unattended phones rather than remote attacks. Bitdefender’s own writeup put it plainly: it is all too common for a device to be left unattended, or snatched from a bag, or handed to someone you think you can trust.
Three Strikes Against the Same Lock
This is not the first time Gemini’s lock-screen powers have cracked open. It is the third distinct incident in less than a year, each one closing one door while leaving, or opening, another.
| Bypass | First Surfaced | Entry Point | Outcome |
|---|---|---|---|
| Original lock-screen bypass | September 2025 | General Gemini lock-screen access | Patched; reporting researcher paid through Google’s Vulnerability Reward Program |
| Deep Research bypass | May 2026 | Gemini’s Deep Research tool, reproduced on a fully patched Pixel 6a | Publicly documented; a separate class of bug from the SMS flaw |
| Add attachment/Continue bypass | Reported since May 2026; disclosed July 17, 2026 | Simultaneous tap of Add attachment and Continue during the PIN prompt | Google confirmed; fix rolling out the week of July 17 |
Google previously acknowledged and patched a related Gemini lock-screen bypass that was rewarded through its Vulnerability Reward Program and publicly detailed in September 2025. Then, months later, someone found another way in through a completely different tool. In May 2026, a security researcher published a write-up describing how they had reproduced the problem on a fully patched Pixel 6a, using Gemini’s Deep Research feature as the entry point. A fully patched phone still let it through, just through a different door.
People who track these bugs closely describe the pattern as structural rather than accidental. The deeper issue is architectural: whenever an assistant is granted a special lock screen context, every feature it can reach, attachments, app linking, external integrations, needs to inherit and enforce that same restricted state. A gap in any single sub-feature is enough to undermine the whole protection. Patch one sub-feature and the restriction still has to be re-proven everywhere else Gemini can reach.
A Feature Google Kept Expanding
None of this existed by accident. Google built Gemini’s lock-screen reach one release at a time, trading a bit of friction for a lot of convenience each time.
The AI assistant first learned to answer basic questions on a locked screen, the kind of thing that used to require unlocking the phone just to check the weather. Google’s AI assistant, Gemini, can now answer general questions on Android phones without needing to unlock the device, a significant improvement since previously even simple questions, like weather updates, required unlocking the phone.
Then Google went further. Google rolled out a new setting for Gemini’s Android assistant that lets you access the AI without unlocking your phone, and shortly after added the ability to place calls and send texts the same way. Google’s own support documentation still spells out the trade being made: users can ask Gemini to make calls and send text messages without ever unlocking the device. Later updates layered on smart-home control and third-party extensions from the same locked-screen entry point. Every addition was a convenience win. Every addition was also one more sub-feature that had to correctly enforce the same restricted, unauthenticated state, and the last three bugs show that enforcement has failed three separate times.
Which Phones Are at Risk?
Right now, nobody outside Google has a full list of vulnerable devices, and even Google has not published one. Here is the split between what has been confirmed and what remains open.
- What we know: The bug affects Android 16 phones with Gemini’s lock-screen messaging turned on, and it is not limited to Pixel hardware.
- What we know: The vulnerability was uncovered by a security researcher and reproduced by The Register on a Pixel 6a running Android 16.
- What we know: Google has developed a fix and says it is shipping this week.
- What’s unconfirmed: Early reports reproduced the bug on a Pixel 6a and on some Samsung Galaxy devices, but not every Samsung user could trigger it, and the variability likely depends on the exact version of the Google app, Gemini app, and Android OS installed, plus OEM customizations.
- What’s unconfirmed: Google said the bug is not Pixel-specific but fell short of specifying which manufacturers, models, or versions are vulnerable.
- What’s unconfirmed: Whether every affected phone has actually received the fix. As of two days after Google’s confirmation, there was no clear device-by-device confirmation that the patch had reached every affected handset.
For IT teams managing large fleets of Android devices, that gap in confirmation matters more than it might for a single owner. The absence of a precise inventory makes blanket policy recommendations tricky, but the safe approach is to assume any Android 16 device with lock-screen Gemini messaging turned on is vulnerable until a patch is explicitly verified.
What to Turn Off Before the Patch Lands
Until every device is confirmed patched, the practical fix sits in the settings menu, not in Google’s changelog. Security researchers reviewing the bug converged on the same short list of steps.
- Install the latest Android system update and Google Play system update available for the device.
- Turn off Gemini’s lock-screen access setting entirely, or at minimum disable the calls-and-messages toggle inside it.
- Disable lock-screen access to calls, messages, and other sensitive actions wherever device settings allow it.
- Hide sensitive notification content from appearing on the lock screen.
- Use a longer PIN or an alphanumeric password rather than a simple four-digit code, understanding that this step alone will not close this specific hole.
A strong PIN does not fix this particular software issue, but it still narrows other, older lock-screen risks while the Gemini patch finishes rolling out. Google has not said whether the fix arrives through a Gemini app update, a Play system update, or a full Android security patch, which is part of why device owners cannot simply wait and assume it applied itself.
Frequently Asked Questions
Are there two different gestures that trigger this bug?
Yes. Most reports describe pressing Continue and Gemini’s Add attachment button at the same time, but some reports also describe a related version of the exploit triggered through a specific multi-touch gesture rather than the button tap method, meaning there may be more than one route into the same authentication gap.
Has Google paid a bug bounty for a Gemini lock-screen flaw before?
Yes. Google previously acknowledged and patched a related Gemini lock-screen bypass that was rewarded through its Vulnerability Reward Program and publicly detailed in September 2025, separate from both the May 2026 Deep Research bug and this latest one.
Does a stronger PIN stop the attack?
No. Security guidance around the bug is explicit that a stronger PIN does not fix this particular software issue, since the flaw bypasses the PIN check entirely rather than guessing it.
Which phone has The Register actually confirmed the bug on?
The vulnerability was uncovered by a security researcher and reproduced by The Register on a Pixel 6a running Android 16, though Google says the underlying flaw is not limited to that model or to Pixel hardware generally.
What should I do if I get a call claiming a family member has been kidnapped?
Do not hang up, but try to verify independently. The FBI’s Chicago field office recommends families agree in advance on a code. As the bureau advises, having a password that family members can ask for in an emergency helps confirm that a loved one is really in trouble, which matters more now that a stolen phone can be made to send convincing messages in the owner’s name.





