Google and security researchers confirmed an Android vulnerability involving artificial intelligence assistant Gemini that allows physical users to send messages without unlocking the device.

The security flaw requires physical access to the smartphone and cannot be exploited remotely. Experts warned that the risk remains significant if a mobile device is lost, stolen, or left unattended for even a few minutes.
Gemini lock screen bypass details

According to a report published by Mashable, the vulnerability affects how Gemini interacts with the Android lock screen. While the assistant is designed to provide specific functions without requiring a full device unlock, researchers found that certain interactions bypass screen protections to reach restricted tools without entering a PIN.
Security specialists highlighted that the flaw specifically enables making calls and sending SMS messages directly from a locked handset. Anyone who gains physical possession of the phone for a brief period can use Gemini to initiate actions without going through standard authentication procedures.

The exposure raises concern because modern smartphones contain vast quantities of personal information, including private conversations, photos, contact lists, financial details, and online account access. Google has acknowledged the issue and stated it is preparing a security patch to fix the flaw.
Google security patch and user protections
Google aims to reinforce authentication requirements to prevent Gemini from performing sensitive actions while an Android phone stays locked. The fix will be distributed through a standard security update that users must install once it becomes available for their devices.

While awaiting the official update, experts advised users to review their Gemini configuration and limit or disable its operation from the lock screen. Security specialists also recommended installing the latest operating system updates and keeping mobile phones secured in public spaces.
The incident reflects a broader challenge across the technology industry as artificial intelligence tools gain expanded capabilities to manage messages, open applications, and alter system settings. Analysts noted that advancing AI features requires stronger authentication frameworks to prevent virtual assistants from becoming new vectors for unauthorized access.
