Security News

Cybersecurity news aggregator

MEDIUM Vulnerabilities SC Media

Android lock screen vulnerability allows Gemini to send messages without PIN

  • What: A vulnerability in Android allows sending messages via Gemini without a PIN.
  • Impact: Physical access to a device can lead to unauthorized message sending.
Read Full Article →

Application security Android lock screen vulnerability allows Gemini to send messages without PIN July 20, 2026 Share By SC Staff (Adobe Stock) A security flaw in Android devices allows unauthorized users to send SMS and WhatsApp messages using Gemini from the lock screen, even without knowing the device's PIN. Google has acknowledged the vulnerability and plans to release a fix this week, based on information published by The Register. The vulnerability requires physical access to an Android device and involves a specific multi-touch gesture. Users can exploit this by simultaneously pressing Gemini's "Add attachment" button and the "Continue" prompt when Gemini requests access to an app like Messages. This bypasses the PIN authentication, allowing an attacker to send SMS messages. Further exploitation can grant Gemini access to other applications, such as WhatsApp, by typing "@WhatsApp" in the Gemini text window, again without requiring a PIN. While physical access vulnerabilities are often downplayed, the potential for misuse in scenarios like fake kidnapping scams, especially given the prevalence of phone theft, warrants attention. Google has confirmed the bug is not specific to Pixel devices and has implemented a fix scheduled for deployment this week. Source: The Register SC Staff Related Application security More Mythos-like models are coming — what organizations can do now Laura French July 20, 2026 These capabilities may be impossible to contain, forcing defenders to contain their impact. Application security Over 1 million malicious emails found using text salting to fool AI scanners Laura French July 17, 2026 Text salting fills emails with hidden benign content to mask malicious phishing lures. Application security Period tracking app Stardust shares sensitive user data with third parties, report finds SC Staff July 16, 2026 Mozilla's investigation revealed that Stardust shared user data, linked to a unique identifier instead of a name, with RudderStack. Related Events Cybercast Bridging the Gap from CISO-Developed Tools to Black Hat Hype: What AI Security Leaders Should Watch Next On-Demand Event Cybercast Protecting Application User Data for Better Privacy, Governance, and Compliance On-Demand Event Cybercast The Next Evolution of Application Security: AI- Accelerated DevSecOps On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Banner Browser Cache Cramming Common Gateway Interface (CGI) Client Cookie DLL Injection Dynamic Link Library You can skip this ad in 5 seconds

Share this article