惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
Docker
Apple Machine Learning Research
Apple Machine Learning Research
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 三生石上(FineUI控件)
月光博客
月光博客
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
WordPress大学
WordPress大学
Hugging Face - Blog
Hugging Face - Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
M
MIT News - Artificial intelligence
腾讯CDC
B
Blog RSS Feed
H
Help Net Security
J
Java Code Geeks
有赞技术团队
有赞技术团队
Y
Y Combinator Blog
博客园_首页
Last Week in AI
Last Week in AI
博客园 - 【当耐特】
博客园 - Franky
B
Blog
MongoDB | Blog
MongoDB | Blog
博客园 - 叶小钗
Martin Fowler
Martin Fowler

GRAHAM CLULEY

'Anne Hathaway' admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars Smashing Security podcast #484: How websites are tracking you with silence CRPx0 ransomware: what you need to know The US military just turned off ad tracking on its phones. Maybe you should too How a hole in Lenovo's login system let hackers walk into 5,000 Dropbox accounts Smashing Security podcast #483: This AI helps thieves steal your iPhone Revolut scam steals £180,000 from Jersey residents in just four weeks Shai-Hulud hackers: two men charged over TeamPCP's global supply chain crime spree that hit OpenAI, and thousands more US Navy tells sailors and their families: scrub your social media, enemies are watching Smashing Security podcast #482: This hacker leaked GTA 6 - and launched their own cryptocurrency Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials Gunra ransomware: what you need to know Smashing Security podcast #481: Never say this to a robot dog Prison for data analyst who tried to extort $2.5 million from his employer An "invisible" car? Researcher uses machine learning to hide vehicles from Flock cameras Smashing Security podcast #480: This is the AI service you should never sign up to Meta's Ray-Bans are being banned from pubs, restaurants, and theatres Beware cut-price AI services that read your every word Apple's bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency Fake IRS letters target cryptocurrency holders The $5 million threat: AI Is supercharging phishing attacks North Korea's elite hackers turned on their own government — and got caught Smashing Security podcast #478: This job interview could destroy your company OpenAI's AI "goes rogue" and hacks Hugging Face: what you need to know Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker Ukraine warns fake CAPTCHAs are being used to make you hack yourself Anubis ransomware: what you need to know Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers
Google's Gemini lets strangers send messages from your lo...
Graham CLULEY · 2026-07-18 · via GRAHAM CLULEY

Gemini, Google's AI assistant, is supposed to make life easier for Android smartphone owners. But right now it may also be making life easier for anyone anyone who happens to pick up your phone.

As The Register reports, Google is working on a fix for a vulnerability that allows an attacker with physical access to a locked Android 16 device to use Gemini to send SMS messages and WhatsApp texts, without ever needing to enter a PIN.

So, imagine the scene. Someone gets hold of your locked Android phone and, despite not knowing your security PIN, they can send messages via SMS or WhatsApp pretending to come from you.

The Register says that it has received multiple reports since May of how it is possible to bypass authentication on Android 16 devices that have enabled Gemini access from the lock screen.

In May 2026, a security researcher published a write-up describing how they had reproduced the problem on a fully patched Pixel 6a, using Gemini's Deep Research feature as the entry point.

It is clear that Google has patched Gemini lock screen issues before, but security researchers keep finding new ways through.

The latest vulnerability is different from the previous similar Gemini-based Android lock screen bypass bugs that have been plaguing the operating system since September 2025.

This latest exploit requires a specific multi-touch gesture. When Android devices have revoked Gemini's access to apps like Messages, and someone tries to send an SMS via Gemini on the lock screen, the user is prompted to enter a PIN. However, when "Continue" is pressed simultaneously with Gemini's "Add attachment" button, the device allows the SMS to be sent without any authentication.

An attacker can then enable Gemini's access to other previously disconnected apps. All they have to do is invoke the relevant prompt by - for instance - typing "@WhatsApp" in Gemini's text window. Once again, no PIN is requested or required.

What makes this particularly sneaky is that the changes are not temporary. If a victim later unlocks their phone and checks their Gemini settings, they will find that WhatsApp has been connected to Gemini, even though no PIN was ever entered.

Of course, exploiting a vulnerability like this does require physical access to a vulnerable Android device. This is not an attack which can be carried out by a remote hacker. But, as we all know, it is all too common for a device to be left unattended, or snatched from a bag, or handed to someone you think you can trust.

A spokesperson at Google told The Register that this new bug is known about, and that a fix is scheduled to be rolled-out this week. But in the meantime, you would be wise to restrict what Gemini can access from your lock screen.

To do that:

  • Open the Gemini app, tap your profile picture, go to Settings, and select "Gemini on lock screen."
  • Turn off "Use Gemini without unlocking" entirely, or (if you are not comfortable with that) disable "Make calls and send messages without unlocking."

Google will no doubt patch this particular bug. But the underlying problem is still present. Every new capability Gemini is given at the lock screen is also a new potential attack surface. The more useful your AI assistant becomes without you needing to unlock your phone, the harder it becomes to guarantee that only you can use it.