Android 16 Security Flaw

Android Bug Lets Attackers Send Messages Despite Screen Lock

Bug, Android 16, Google, Android bug, Android 16 bug, Android 16 bug allows messages without PIN, Android 16 lock screen security vulnerability, Google Gemini lock screen vulnerability, Android, Vulnerability
Facebook
X
LinkedIn
Reddit
WhatsApp
Source: David Marin Foto / Shutterstock.com

A bug in Android 16 allows SMS and WhatsApp messages to be sent through Google Gemini without entering a PIN. Google is expected to roll out a security update shortly.

Google is working to fix a security flaw in Android 16 that allows unauthorized individuals with physical access to a device to send text messages via SMS and WhatsApp. The vulnerability affects the integration of the Gemini AI assistant on the lock screen. Under normal circumstances, the system prompts users to enter their PIN when sensitive functions or external apps are launched.

Ad

However, a flaw in the way the system processes certain interactions can bypass this security barrier. If a user simultaneously taps the button to continue and the option to add a file attachment on the display, the authentication check is skipped. The system then grants access to the messaging service, even if access had previously been disabled in Gemini’s settings.

Broad Access to User Data

Once the screen lock has been bypassed using the specific gesture, attackers can do more than send messages on their own. The issue is related to how processes are handed off between the lock screen interface and regular applications. The flaw can be used to independently re-enable app permissions that had previously been revoked for Gemini.

It is also possible to view or delete the AI assistant’s chat history, modify certain smartphone security settings, and extract local data. The flaw was reproduced, among other devices, on a Google Pixel 6a running the latest available software updates.

Ad

Physical Access Required and Temporary Workarounds

Exploiting the vulnerability requires an attacker to have physical possession of the smartphone. Security researchers nevertheless warn of the risks in the event of theft, as the feature could be abused to send fake messages or extortion attempts to contacts while impersonating the legitimate device owner.

A Google spokesperson confirmed that a fix for the software bug has already been developed, with the security update scheduled to roll out during the current week. Until the patch is installed, users can reduce the risk by disabling Gemini’s use on the lock screen in their device settings or completely turning off permission for calls and messages while the device is locked.

(ll)

Ad

Artikel zu diesem Thema

Weitere Artikel