Researchers and multiple reports to The Register describe a vulnerability in Android 16 that can allow an attacker with physical access to a locked device to send SMS or WhatsApp messages via the Gemini AI, even without knowing the device passcode, if Gemini is accessible from the lock screen.
What happened
According to reports, the issue can be triggered by a multi-finger gesture on the lock screen which launches the Gemini AI app. Once running, Gemini can be instructed to use WhatsApp, the Phone app, or Messages to send communications on behalf of the device owner.
If Gemini does not already have permission to an app such as Messages, the system normally prompts the user to open the requested app, which typically requires unlocking the device. The vulnerability arises when an attacker presses the “continue” button multiple times in combination with Gemini’s “add attachment” control; due to a software bug, this sequence can allow an SMS to be sent without entering the passcode.
Reports also indicate that, after exploiting this flaw to gain access to a messaging app, an attacker can grant Gemini access to additional apps.
Risk and limitations
The exploit requires physical possession of the device; there are no public reports of remote exploitation. Therefore, the vulnerability is primarily a threat in scenarios where a phone is stolen or temporarily in an attacker’s hands.
Google’s response
Sources say Google is already aware of the problem. A patch may be released at any time, and a software update would likely mitigate the issue.
Recommendations for users
Given the current public information, users can reduce exposure by disabling Gemini access from the lock screen or ensuring their device is not left accessible to others. Because the exploit needs physical access, preventing unauthorized possession of the device is the most effective immediate safeguard.
Conclusion
The reported Android 16 bug can let Gemini running from the lock screen send messages without a passcode when an attacker has physical access and Gemini is enabled. Google has been informed and is expected to release a fix.



