A security vulnerability has been detected on the Android lock screen that allows sending SMS via Gemini. Google is preparing an update to fix the problem.
Gemini assistant in the Android operating system came to the fore with a security vulnerability that allows unauthorized operations via the lock screen. This allows messages to be sent even when the device is locked.
The vulnerability in question occurs in scenarios where users restrict access to Gemini’s messaging applications. Under normal circumstances, when a notification is wanted to be sent from the lock screen, the system takes security measures by requesting a PIN code.
How is the vulnerability triggered?
This security vulnerability on the lock screen is triggered by using two buttons on the user interface simultaneously. When users press the “Add plug-in” and “Continue” buttons simultaneously while interacting with Gemini on the lock screen, the PIN verification screen is disabled.
This misconception is not limited to sending SMS only and provides access to broader powers. According to the information shared, even WhatsApp access, which was previously disabled from Gemini settings, can be activated again with this procedure.
Update statement from Google
This vulnerability, detected in Android 16 version and reported since May, is defined as a known problem by Google. The company continues to work on an update that will fix the error in question.
It is stated that the vulnerability affects not only Pixel devices but also other devices using different Android versions. There is currently no definitive list of which Android versions are affected by this situation.
Similar lock screen bypass formulas are among the technical difficulties encountered from time to time in portable operating systems. Similar vulnerabilities are among the topics that are being researched and worked on for different purposes on the iOS side.
What do you think about this vulnerability?