Google has officially confirmed that there is a serious security flaw in all Android devices running Android 16. This flaw allows the Gemini AI to send SMS and WhatsApp messages without authorisation, even before the smartphone has been unlocked.
This is because Gemini is integrated into the lock screen and therefore has easy access to it. There is no need to enter a PIN first. This can be not only annoying but also dangerous, as attackers can gain access to text messages or sensitive data that should normally remain behind the lock screen.
As reported by The Register, Android devices from all manufacturers are affected, not just Google’s own Pixel phones. However, to exploit the bug, direct access to the smartphone would be required – for example, if the device is stolen or lost.
How to protect yourself
To prevent this vulnerability from affecting your device’s security, you can deny Gemini access to your lock screen.
To do this, open the Gemini app on your Android smartphone, tap your profile picture and then go to Settings. There, select ‘Gemini on lock screen ’ and disable the option ‘Use Gemini without unlocking ’ or, alternatively, ‘Reply on lock screen’.
You can also restrict Gemini’s access to specific apps and features. To do this, find the ‘Gemini App Activity’ menu item and then select ‘Extensions’. Deselect any apps that you do not want Gemini to have access to (such as Google Messages, email apps or WhatsApp).
A Google spokesperson told The Register that the company has already found a solution to the problem. This is due to be rolled out via an Android update later this week. So make sure you keep your device’s Android version up to date to receive such fixes promptly.