Android 16 Bug Lets Gemini Bypass Lock Screen to Send Messages

Google is fixing an Android 16 bug that lets Gemini bypass lock screen authentication to send SMS and WhatsApp messages. The flaw, discovered by Bitdefender, affects multiple devices and raises serious security concerns about AI on the lock screen.

Last Updated: July 28, 2026 Editorial Process
Editorial Process
See more of Inside AI's trusted news by adding us as a preferred source on Google.
AI neural network visualization
Published on: July 20, 2026

July 20, 2026, (Inside AI) — Google is rushing a fix to Android 16 devices after security researchers uncovered a bug that lets its Gemini assistant send SMS and WhatsApp messages from a locked phone without a PIN. The flaw, an authentication bypass, undermines lock screen protections and affects any Android 16 device with Gemini enabled on the lock screen.

The mechanics of the exploit are deceptively simple. Normally, if a user has revoked Gemini's access to an app like Messages, asking Gemini to send a text from the lock screen triggers a PIN prompt before the action can proceed. The flaw appears when two on-screen actions are performed at the same time: pressing "Continue" while simultaneously tapping Gemini's "Add attachment" button. Rather than enforcing the PIN check, the device lets the SMS go through unauthenticated.

The consequences reach further than a single unauthorized text. An attacker can type a command such as "@WhatsApp" into Gemini's text field to re-link an app that the owner had explicitly disconnected, again without any PIN, password, or biometric check. Checking a device's settings afterward would show WhatsApp reconnected to Gemini as though the owner had approved it themselves, even though the required authentication step never actually happened.

That persistence is what elevates this beyond a nuisance bug. An attacker who restores Gemini's WhatsApp access during a brief window of physical access could exploit that reconnected integration again later, without needing to touch the phone a second time.

The Register has received multiple reports since May describing users bypassing device authentication on Android 16 devices that enable Gemini access from the lock screen. These are distinct from similar Gemini-based Android lock screen bypass bugs that made the rounds since September 2025. That earlier wave of incidents, which raised the same fundamental concerns about AI assistants and lock screen security, apparently did not prompt a comprehensive architectural fix before Gemini's lock screen capabilities were expanded further.

Bitdefender researchers first flagged the current issue in May after producing a reproducible exploit on a fully updated Pixel 6a. A technical report detailed how the simultaneous multi-touch sequence skips the authentication prompt entirely. Google confirmed that the bug extends beyond Pixel devices, though it has not released a full list of affected models or Android versions.

Google was reportedly informed of this vulnerability in May 2026. It is now mid-July, roughly ten weeks between disclosure and a public fix arriving. Google has not explained the delay. A company spokesperson confirmed that engineers developed a patch and began a wider rollout this week, urging users to install the update immediately. Until the patch is confirmed on a given device, users who do not regularly use Gemini from the lock screen may want to disable lock screen access as an extra precaution.

The practical threat model is worth understanding clearly. The exploit requires physical access to the device, so this is not a remote attack. But the risk is not trivial. A phone left briefly on a desk, handed to someone for a moment, or stolen, is enough to open the window. If an attacker restores Gemini's WhatsApp access, they can later use the AI to read or send messages, perhaps when the phone is briefly unattended again. Once the integration is live, future exploits could be faster and harder to spot.

The corporate security implications are also real. Many employees use personal Android phones for multi-factor authentication, Teams chats, email, and password recovery. A compromised SMS or WhatsApp channel from a trusted number can bypass verification steps, reset passwords, or deceive coworkers. The bug does not directly target enterprise systems, but it creates a credible impersonation path that can.

Security experts have pointed to the incident as evidence of a structural problem with how on-device AI is being integrated into security-sensitive contexts. Convenience features like messaging directly from the lock screen compress the space between the AI assistant and authenticated actions, and bugs in that compressed space can have outsized consequences. The industry consensus is moving toward hardware-backed authentication and stricter API controls as the baseline for any AI feature that touches communications or permissions.

This incident will not be the last of its kind. As AI assistants become more capable and more deeply embedded in mobile operating systems, the attack surface they introduce grows proportionally. Google's willingness to confirm the issue and push a patch is a step in the right direction, but the ten-week gap between private disclosure and public fix points to a process that needs to move faster when the vulnerability sits at the intersection of AI and physical device security.

More from Inside AI

  • AI In Business

    Nvidia Acquires Hugging Face for $12.9 Billion in Strategic Open AI Move

    September 3, 2026
  • AI In Business

    LinkedIn’s Prashanthi Padmanabhan on AI-Powered Hiring and Agentic Recruiting

    September 3, 2026
  • Generative AI

    AI-Generated Ads Perform Worse Than Human-Made Ones, Research Shows

    September 3, 2026
  • AI Tools

    Abu Dhabi AI Institute Releases Six Fully Open-Source Models with Training Data and Code

    September 3, 2026
  • AI Policy & Regulation

    Anthropic Still Flagged as Supply Chain Risk by Pentagon, US Official Says

    September 3, 2026
  • AI In Business

    Nscale Commits $3.5 Billion in Compute for Figure’s Humanoid Robots

    September 3, 2026
  • AI Policy & Regulation

    New York City Unveils AI Policy for Children, Anthropic Wins Court Battle Against Pentagon

    September 3, 2026
  • Generative AI

    Meta Says Muse Spark 1.3 Finally Caught Up With OpenAI and Anthropic

    September 3, 2026

Never Miss a Breakthrough

Join 50,000+ readers who get our daily AI intelligence briefing. No fluff, just what matters.

Inside AI is an independent publication covering artificial intelligence news, machine learning research, and the tools shaping the future of technology. No hype. Just what's happening in the AI world.

Topics

  • Artificial Intelligence
  • Machine Learning
  • Generative AI
  • Agentic AI
  • Vibe Coding
  • Prompt Engineering
  • AI Policy & Regulation
  • AI Hardware & Infrastructure
  • AI Tools
  • AI In Business
  • Robotics
  • Cybersecurity AI
  • AI Safety
  • AI Tools & Reviews (Coming soon)

Company

  • Editorial Standards
  • Privacy Policy
  • Terms of Service
  • Contact
  • About Us

Others

  • Press Releases
  • Features
  • Sponsored Content

© 2026 Inside AI. All rights reserved.

Designed by Blue Flare Digital