Ad

A newly discovered vulnerability allows users to bypass lock screen authentication on Android devices using Gemini. This flaw, known as an authentication or lock screen bypass, affects more than just Pixel devices. Google has acknowledged the issue and is working on a fix.
The vulnerability occurs when a user disables Gemini's access to certain apps, such as Messages. Normally, if someone tries to use Gemini from the lock screen to send a message, the device requests a PIN. However, the flaw appears when the user presses the "Add attachment" button at the same time as the Continue button. This action bypasses the PIN prompt, granting unauthorized access.
The issue does not stop at SMS privileges. In a demonstration video, an attacker re-enabled access to WhatsApp, even though it had been previously disabled in Gemini's settings. This suggests the vulnerability could allow broader access to apps and data than intended.
The vulnerability has been reported since May on Android 16. Google has confirmed awareness of the issue and has stated that a fix is in development. While the flaw affects Pixel devices, there is no definitive information on which other Android versions or devices are vulnerable.
This type of security issue is not unique to Android. Similar vulnerabilities have been found on other platforms, including iOS. Online communities often search for such bypasses, sometimes with malicious intent, such as unlocking and reselling stolen phones.
Authentication bypass vulnerabilities can compromise user privacy and device security. They allow unauthorized users to access restricted apps and features without proper authentication. Users are advised to stay alert for software updates and apply security patches as soon as they become available.
Ad
Ad
What Matters Most
One email each morning: the launches,
the price changes and the reviews
worth reading.
Ad
Ad