Google says a fix is coming this week for an Android flaw that lets anyone holding a locked phone use Gemini to send a text message with no PIN required. The trick takes two thumbs and about a second: tap the assistant’s Continue and Add attachment buttons at the same moment, and the lock screen’s authentication check never fires.
It is the third distinct way researchers have found to beat Gemini’s lock screen guardrails since September 2025. Google confirmed this version of the bug on July 17, 2026, a single day after European regulators ordered the company to give rival AI assistants, including ChatGPT and Claude, that same category of system level access across Android.
Two Taps Undo Android’s Whole PIN Screen
Android 16 lets Gemini answer from the lock screen without unlocking the phone first. Google added the ability to send messages without unlocking in January 2025, and plenty of owners use it to fire off a quick reply without keying in a PIN every time.
The safeguard is supposed to kick in the moment Gemini reaches for something the owner has switched off. If someone has revoked the assistant’s access to Google Messages and a stranger tries to send a text through Gemini from the lock screen, the phone is supposed to demand the PIN before anything goes out. The bypass takes over from there in five quick steps:
- The device owner turns off Gemini’s access to Messages in Settings, a sensible precaution against a stolen or borrowed phone.
- Someone holding the locked phone summons Gemini from the lock screen and asks it to send a text.
- Gemini prompts the user to hit Continue, which is supposed to trigger a PIN screen before anything sends.
- Tapping Continue and Gemini’s Add attachment button at the exact same instant skips the PIN entirely, and the message goes out.
- Typing “@WhatsApp” into the same Gemini window silently reconnects WhatsApp access too, again with no PIN.
Security researcher David Schutz shared a demonstration of the sequence, showing Gemini sending a text after Messages access had already been switched off in its own settings. Checking Settings afterward shows WhatsApp linked to Gemini as if the owner had approved it, even though no PIN was ever entered. The change sticks and does not reset itself once the phone is unlocked normally.
The Third Time This Lock Screen Has Failed
This is not the first Gemini lock screen bug, and researchers who track the pattern doubt it will be the last. A researcher at the security firm Payatu disclosed a race condition between Bixby and the keyboard toggle on September 10, 2025, after reporting it to Google’s Vulnerability Reward Program that March. That version worked on a Galaxy S23 FE and a Pixel 7 Pro running Android versions 13 through 15.
A second version surfaced in the spring of 2026. A researcher reproduced a similar bypass on a fully patched Pixel 6a, this time using Gemini’s Deep Research feature as the way in rather than the SMS flow. The person who found it had assumed the earlier chapter was closed after Google’s 2025 fix. It was not.
| Disclosed | Entry Point | Device Tested | Outcome |
|---|---|---|---|
| September 10, 2025 | Race condition between Bixby and the keyboard toggle | Galaxy S23 FE and Pixel 7 Pro, Android 13 to 15 | Patched after a Vulnerability Reward Program payout |
| Spring 2026 | Gemini’s Deep Research feature | Pixel 6a, fully patched Android 16 | Reported unresolved by the researcher who found it |
| July 2026 | Simultaneous tap of Continue and Add attachment | Android 16 devices, not limited to Pixel | Fix scheduled by Google this week |
Three bugs in under a year point to the same design choice rather than three unrelated slip ups. Bitdefender’s security researchers, who have tracked the pattern since the first bug surfaced, wrote that “every new capability Gemini is given at the lock screen is also a new potential attack surface.”
Google Says a Patch Is Already Rolling Out
A Google spokesperson told The Register the bug is real, that it is known internally, and that a fix was scheduled for full deployment this week. The company also said the flaw is not limited to Pixel devices, though it stopped short of naming which other manufacturers are affected.
Exploiting the bug requires physical possession of the phone, not a remote connection. That limits the danger but does not remove it. Phones get left on cafe tables, handed over for a quick photo, or snatched during a commute, and the window for this trick is measured in seconds. The Register, which said it has fielded reports of the bug since May 2026, argued the flaw still matters given “the potential to send convincing SMS messages as part of fake kidnapping scams.”
What We Know:
- Google confirms the bug is real, reproducible on Android 16 phones with Gemini’s lock screen messaging switched on, and not exclusive to Pixel hardware.
- A fix is scheduled for release this week, according to a Google spokesperson who spoke with The Register.
What’s Unconfirmed:
- The exact rollout date or build number beyond “this week,” and whether every carrier variant gets it at once.
- Whether the fix arrives through a Gemini app update alone or needs a broader Android security patch.
A message sent this way does not by itself hand an attacker your other accounts. The bypass sends outgoing texts. It does not give access to the incoming verification codes that many services still use for sign in and password recovery.
Why Is This Bug Landing Days After an EU Order?
Google confirmed the fix on July 17, 2026, one day after the European Commission ordered it to give rival AI assistants the same lock screen level access Gemini already has on Android. The July 16, 2026 order covers 11 Android features, including the kind of screen and context reading this bug abuses, and it targets competition rather than security.
Under the ruling, competing assistants such as ChatGPT and Claude must eventually get the same wake word activation, screen and app context reading, and cross app control that Gemini already performs on Android, once they clear security and privacy criteria that Google itself gets to set. The Commission wants rival AI services to compete on equal Android footing with Gemini rather than being boxed in as ordinary downloaded apps.
The two changes run on different clocks. The Android changes reach EU users starting in July 2027, while a separate requirement to share anonymized Google Search data with rivals takes effect in January 2027.
Henna Virkkunen, the Commission’s executive vice president for tech sovereignty, security and democracy, said the goal is to see “emerging alternatives to Google Search and Google’s AI services, such as Gemini,” giving EU users more choice over which assistant runs their phone.
Google’s Security Vetting Faces a Bigger Test
Outside analysts had flagged the risk before this particular bug ever surfaced. A review of the Commission’s technical annex found the mandate extends to continuous microphone and camera access, on top of the screen reading and cross app control already planned, the same categories of privilege behind this week’s SMS bypass.
The International Center for Law and Economics, a research group that has tracked the EU’s antitrust cases against Google, described the resulting mandate this way:
An attack surface qualitatively different from anything Article 6(7) has previously been used to open.
That comparison was against Apple’s narrower 2025 interoperability rules, which covered bounded functions like NFC and Bluetooth pairing rather than screen content or always on wake word listening.
The Commission opened parallel proceedings into Android access and search data on January 27, 2026, the same month Google finished retiring Google Assistant in favor of Gemini as Android’s default assistant. Teresa Ribera, the Commission’s competition chief, said the goal is to make sure “the playing field is open and fair, not tilted in favour of the largest few.”
Google can still screen every applicant before switching on access, assessing whether a rival meets its own cybersecurity and data protection standards. That vetting process will now run on a lock screen architecture that has been beaten three times in under a year.
Frequently Asked Questions
How do I stop Gemini from bypassing my lock screen right now?
Turn off the feature rather than trust the permission toggle. Google’s own mitigation advice is to go to Settings, then Apps, then Gemini, then Permissions, and disable lock screen access entirely, or go to Settings, then Display, then Lock screen, and turn off the AI shortcut there. Neither is permanent, but both remove the entry point until the patch installs.
Does turning off Gemini’s access to Messages protect me?
That setting alone will not stop it. The whole flaw is that Gemini’s lock screen flow can re-enable an app the owner switched off without ever asking for the PIN it is supposed to require. Disabling Gemini’s lock screen access altogether is the safer step, not just revoking its access to individual apps.
Is this bug limited to Pixel phones?
No. Google told reporters it is not Pixel specific, though some users say they could not reproduce it on Samsung devices. The company has not named which manufacturers or Android skins beyond Pixel are affected, so anyone running Android 16 with lock screen Gemini access enabled should treat the risk as brand independent until the patch confirms otherwise.
What is Google’s Vulnerability Reward Program, and did it catch this bug?
It is Google’s bug bounty scheme for security researchers, and payouts for the most severe Gemini related flaws can reach up to $20,000 for a single report. This particular bypass reached the public through press reporting rather than a published bounty writeup, so it is not yet clear whether it will qualify for a reward under that program.
Do iPhones have similar lock screen bypass problems?
Yes, though usually for a different reason. Dedicated online communities hunt for the same kind of lock screen edge cases on iPhones, but the goal there is more often unlocking and reselling stolen handsets than sending an unauthorized text.





