news.mlab.sh
Back to the feed
threat-intel

Google’s Gemini lets strangers send messages from your locked Android phone

Medium
Summary

Google’s Gemini AI assistant on Android 16 devices has a vulnerability that allows unauthorized users to send SMS and WhatsApp messages from a locked phone. This is achieved through a specific multi-touch gesture when Gemini’s ‘Add attachment’ button is pressed simultaneously with a prompt to connect an app, like WhatsApp, without requiring a PIN. Google is aware of the issue and a fix is scheduled for release this week, but users should restrict Gemini’s access from their lock screen.

Google’s Gemini AI assistant, designed to simplify Android smartphone usage, has a security vulnerability that could allow strangers to send messages from a locked device. As The Register reports, a specific multi-touch gesture within Gemini’s interface enables an attacker to bypass authentication and send SMS and WhatsApp messages without needing to enter a PIN.

Researchers have demonstrated this vulnerability on fully patched Pixel 6a devices by leveraging Gemini’s Deep Research feature. The exploit requires a user to trigger a specific prompt – for example, typing '@WhatsApp' in Gemini’s text window – while simultaneously pressing the ‘Add attachment’ button. This bypasses the standard PIN requirement and allows the attacker to send messages as if they were the device owner.

This vulnerability is persistent; even after unlocking the device and checking Gemini settings, WhatsApp will remain connected to the assistant, despite no PIN ever being entered. The issue stems from Gemini’s ability to access apps from the lock screen, and the potential for abuse grows with each new feature added.

Google acknowledges the vulnerability and states that a fix is planned for release this week. However, the underlying problem remains – the more functionality Gemini has access to at the lock screen, the greater the risk of unauthorized access.

Users should consider restricting Gemini’s access to apps from their lock screen to mitigate the risk.

Read the full article at Graham Cluley