Google is rolling out a fix for a newly discovered Android 16 security bug that could let someone misuse Gemini from a locked phone. The flaw may allow a person with physical access to an unlocked screen to send SMS or WhatsApp messages without entering the device PIN.
The issue affects Android 16 devices that support Gemini on the lock screen. Although the attack requires someone to have the phone in hand, security researchers say it can still let an attacker send messages as the phone’s owner. This makes the bug a serious security concern, especially for users who rely on lock screen protections.
Security experts describe the flaw as an authentication bypass or lock screen bypass. Under normal conditions, Gemini should ask for the device PIN before sending messages while the phone is locked. This extra step prevents unauthorized access to messaging features.
However, according to reports, a specific multi-touch action can bypass that security check. As a result, Gemini may send an SMS without asking for the PIN. This means the expected authentication process does not always work as intended.
The issue also goes beyond text messages. Reports show that the same method can restore Gemini’s access to apps that users had previously disconnected, including WhatsApp. Once the connection is restored, Gemini can reportedly send WhatsApp messages from the locked phone without completing the required authentication step.

Security company Bitdefender found another worrying detail. It is reported that the change is not always temporary. After unlocking the phone and checking Gemini’s settings, users may find that the affected app remains connected to Gemini. This can happen even though no PIN was entered during the lock screen interaction.
Reports suggest that researchers first discovered the issue in May. According to some sources, several people reported authentication bypass problems on Android 16 devices with Gemini enabled on the lock screen. Bitdefender also said that a security researcher successfully reproduced the flaw on a fully updated Pixel 6a and published a technical report in May.
This bug is different from previous Gemini-related lock screen bypass issues reported since September 2025. While those earlier flaws involved different methods, the latest issue highlights another weakness in lock screen AI features.
Google also confirmed that the problem is not limited to Pixel smartphones. The company told The Register that the vulnerability affects more than just Pixel devices. However, Google has not shared a complete list of affected manufacturers, phone models, or Android versions. Because of this, the full impact remains unknown.
The company says it is already addressing the issue. A Google spokesperson confirmed that engineers have developed a fix and planned a wider rollout this week. Users should install the update as soon as it becomes available to reduce the risk.
The incident also raises broader concerns about AI features that work from the lock screen. While these tools offer extra convenience, they also increase security risks if they can access messages or other apps without proper authentication.
Similar lock screen bypass techniques have appeared on other platforms, including iOS. Security researchers and online communities regularly test these systems to find unexpected ways to access restricted features on locked devices.
For Android users, the lesson is straightforward. AI assistants should make everyday tasks easier, but they should never weaken the basic security protections that keep personal data safe.
