A critical lock-screen bypass in Android 16 allows anyone holding your phone to send SMS messages through Google Gemini without entering your PIN, even if you specifically cut off Gemini’s access to your messaging apps. Google has acknowledged the vulnerability—first reported to them back in May—and says a fix is rolling out, but as of July 19, there’s no clear device-by-device confirmation that the patch has reached every affected handset. Until you verify the fix yourself, you should turn off Gemini’s ability to send messages from the lock screen immediately.

The bug: a multi-touch timing trick

The vulnerability was uncovered by a security researcher and reproduced by The Register on a Pixel 6a running Android 16. At its core, it’s a timing attack that requires physical possession of the device. The attacker invokes Gemini from the lock screen—often just a long-press of the power button or a swipe from the corner—and asks it to send a text message. Normally, if the user has revoked Gemini’s access to Google Messages, Android will demand the device PIN before proceeding. But here’s the trap: if the attacker simultaneously taps “Add attachment” and “Continue” at the exact moment the PIN prompt appears, the authentication step vanishes. Gemini then treats the request as authorized and fires off the SMS.

That’s all it takes—no malware, no remote exploit, no advanced technical skills. A three-second interaction while a phone is left unattended on a desk, in a bag, or on a gym locker shelf. The attack is entirely local, which limits its scope compared to a network-based exploit, but it’s dangerously practical in everyday settings: workplaces, schools, households, and public spaces.

Not just SMS—it silently reconnects revoked apps

What elevates this from a nuisance to a genuine security failure is that the same technique can re-enable Gemini’s integration with WhatsApp. If a user had previously disconnected WhatsApp from Gemini in the settings, an attacker can type @WhatsApp into the lock-screen Gemini interface and apply the same multi-touch trick. This forces Gemini to reconnect the messaging service without asking for authentication. The change persists, meaning the next time the legitimate owner unlocks the phone, they may not even notice that WhatsApp access has been silently restored.

This isn’t just about sending a rogue text; it’s about undoing deliberate security choices. A victim who thought they had locked down their AI assistant now has a backdoor open for further impersonation. Because the exploit manipulates the permissions layer, it undermines the trust model of Android’s lock-screen boundaries.

Who is affected? Not just Pixel phones

Google has stated the issue is “not limited to Pixel hardware,” though the company hasn’t published a definitive list of impacted devices or builds. Early reports reproduced the bug on a Pixel 6a and on some Samsung Galaxy devices, but not every Samsung user could trigger it. The variability likely depends on the exact version of the Google app, Gemini app, and Android OS installed, as well as OEM customizations and whether the user has enabled lock-screen messaging.

The common thread is Android 16 with Gemini configured to operate while the phone is locked. Specifically, the “Make calls and send messages without unlocking” toggle—found under Gemini’s lock-screen settings—is the onramp for this attack. If that option is enabled, the bug provides a path around the PIN prompt that was supposed to safeguard revoked permissions.

For IT administrators managing fleets of devices, the absence of a precise inventory makes blanket policy recommendations tricky. But the safe approach is to assume any Android 16 device with lock-screen Gemini messaging turned on is vulnerable until a patch is explicitly verified. Even phones that have received a recent security update might not be fixed if the correction wasn’t bundled into that particular rollout.

What’s at stake: beyond SMS impersonation

The most obvious danger is social engineering. An attacker can send a message as you to a family member, colleague, or client, asking for money, sharing a malicious link, or fabricating an emergency. Because the SMS comes from your number, it carries inherent trust. A single well-crafted text could start a chain of events that leads to financial loss or credential theft.

But the WhatsApp reconnection adds a subtler threat. If an attacker restores Gemini’s WhatsApp access, they can later use the AI to read or send messages, perhaps when the phone is briefly unattended again. They might not even need to keep the phone; once the integration is live, future exploits could be faster and harder to spot.

For Windows-centric organizations, the Android lock screen might seem like a separate universe. Yet many employees use personal Android phones for multi-factor authentication, Teams chats, email, and password recovery. A compromised SMS or WhatsApp channel from a trusted number can bypass verification steps, reset passwords, or dupe coworkers. This bug doesn’t directly break Windows authentication, but it creates a credible impersonation path that can circumvent human verification.

The fix: Google’s slow rollout

Google told The Register that it had developed a fix and expected to begin deployment during the week of July 13, 2026. As of July 19, however, no specific Android security bulletin, CVE identifier, Pixel update build, or Gemini app version has been publicly linked to the resolution. The lack of transparency is concerning: users are left guessing whether their device is protected.

Historically, Google distributes patches through multiple channels: monthly Android Security Bulletins, Google Play System updates, Google app updates via the Play Store, and Gemini app updates. It’s possible different devices will receive the correction through different streams. That fragmentation means a user might install the latest Android security patch but still be vulnerable if the core fix is delivered through a Google app or play system update they haven’t yet received.

The timeline is also worth noting. The vulnerability was reported to Google in May 2026, making this a roughly ten-week window from disclosure to public awareness. That’s not unheard of for OS-level patches, but the public disclosure by The Register before a confirmed universal fix puts pressure on users to act now.

What you should do right now

Until you personally see a confirmation that your device is patched—or test the exploit yourself on a spare phone—disable Gemini’s lock-screen messaging features. The steps are straightforward on most Android handsets:

  1. Open the Gemini app.
  2. Tap your profile picture or initial in the top-right corner.
  3. Select Settings > Gemini on lock screen.
  4. Turn off Make calls and send messages without unlocking.

If you’re especially concerned about physical access (the device is often in a shared space, a classroom, or public transit), also turn off Use Gemini without unlocking. This removes Gemini from the lock screen entirely, closing the attack surface completely.

After you’ve made these changes, verify that no unexpected integrations were added. Go into Gemini’s settings and review the list of connected apps—especially Google Messages, Phone, and WhatsApp. If anything looks amiss, disconnect it and consider changing relevant account passwords.

Keep an eye on updates: install all pending Android system updates, Google Play system updates, and app updates for the Google app and Gemini. When Google finally issues an official advisory with a build number or CVE, you’ll be able to re-enable lock-screen messaging if you wish.

The bigger picture: lock-screen convenience vs. security

This incident highlights a growing tension in mobile operating systems. Modern lock screens are no longer inert barriers; they’re active dashboards that show notifications, enable payments, control smart homes, and now host AI agents that can communicate on your behalf. Each new capability introduces fresh interactions, and those interactions can hide subtle bugs.

Gemini’s lock-screen messaging was designed for convenience: hands-free texting and calling while driving, cooking, or otherwise occupied. Google deliberately gave users an opt-in toggle after weighing the risks of someone else picking up the phone. But this bug proves that even an opt-in feature can be weaponized if the underlying permission logic is flawed. The presence of a PIN prompt is meant to guarantee security; when a timing glitch can dismiss that prompt, the promise is broken.

For Windows users who carry Android phones, it’s a reminder to think holistically about security. A locked phone is not a useless brick, and the AI assistants we invite onto our lock screens need far more rigorous permission sandboxing. Google will patch this bug, but similar flaws could emerge in other voice assistants or smart lock-screen features.

Outlook

Google will likely issue a full public advisory in the coming days or weeks, detailing the affected versions and the patch’s delivery mechanism. Until then, treat any Android 16 device with lock-screen Gemini messaging enabled as potentially vulnerable. The practical steps are simple: disable the feature now, check for and apply updates, and re-enable it only after you’ve confirmed the fix is live on your specific device.

For power users and IT admins, testing the bug on a controlled handset after an update can provide an extra layer of assurance. But for everyone else, a few taps in the Gemini settings are all that stand between you and a potential impersonation. In a world where a three-second physical interaction can send texts as you, a little precaution goes a long way.