Android 16 Lock Screen Bug Lets Attackers Send Messages Without a PIN

Android 16 lock screen bug lets attackers bypass PIN to send texts via Gemini; Google confirms fix rolling out.

Jul 20, 2026
4 min read
Technobezz
Android 16 Lock Screen Bug Lets Attackers Send Messages Without a PIN

Don't Miss the Good Stuff

Get tech news that matters delivered weekly. Join 50,000+ readers.

A multi-touch timing trick in Android 16 lets anyone with physical access to a locked phone send SMS and WhatsApp messages through Google Gemini, bypassing the device PIN entirely. Google confirmed the vulnerability and said a fix is rolling out this week.

The exploit targets Gemini's "Make calls and send messages without unlocking" feature, an opt-in convenience meant to speed up hands-free use. But the underlying permission logic contains a flaw that turns that convenience into a backdoor.

The Register reported receiving multiple accounts since May from users who bypassed device authentication on Android 16 phones with Gemini enabled on the lock screen. A security researcher reproduced the bug on a fully updated Pixel 6a and published a technical write-up in May 2026.

Here is how it works. When a device owner revokes Gemini's access to apps like Messages, the chatbot prompts a user to "Continue" to open the app.

Pressing "Continue" simultaneously with Gemini's "Add attachment" button lets the SMS go through without asking for a PIN. Bitdefender noted that the same method restores Gemini's access to WhatsApp, even though the expected authentication step was never completed. The attack requires physical access to the phone, but that is a low bar for a device left unattended on a desk or picked up in a public space.

Google told The Register it is aware of the bug and has already implemented a fix scheduled for full deployment this week. The company did not specify whether the patch arrives via a Google Play Services update, a system update, or a Gemini app update.

This is not the first Gemini lock-screen bypass. Researchers have found similar authentication gaps since September 2025, and each new AI capability introduces fresh interactions that can hide subtle permission bugs.

Google will patch this one, but the pattern raises a question about how deeply lock-screen AI features are audited before they ship.

Share