Android Lock Screen Vulnerability: Gemini Bypass Allows Unauthorized SMS

Source: Date:

Lock screen vulnerabilities can occasionally occur, particularly in complex software that manages numerous edge cases, like Gemini's ability to operate from the lock screen.

In hacking parlance, this issue is classified as an authentication bypass vulnerability or lock screen bypass. It's intriguing to see what potential exploits users uncover or happen upon. A brief video demonstrates the exploit: a user has wisely disabled Gemini's access to certain apps, such as Messages. When someone with physical access to the device attempts to use Gemini to send a message from the lock screen, the phone prompts for a PIN, which is expected.

However, the flaw arises when the user simultaneously presses the “Add attachment” and “Continue” buttons, successfully bypassing the PIN requirement. This not only grants access for sending SMS messages but can also allow unauthorized access to WhatsApp, even if it had been disabled in Gemini's settings. It's a remarkable discovery.

This vulnerability has reportedly been known to Google since May, particularly affecting devices running Android 16. Although a fix is being developed, the issue is not limited to Pixel devices; details about other affected Android versions remain unclear.

Such vulnerabilities are not unique to Android. For example, dedicated online communities actively seek similar bypass conditions on iOS, often with more malicious intentions, such as unlocking and reselling blocked, stolen devices.

Source | Via

Scroll to Top