Particle.news

Google Confirms Android 16 Lock-Screen Bypass Tied to Gemini

A timing flaw in Gemini’s lock-screen shortcuts bypasses PIN checks ahead of a planned patch this week.

Overview

  • Google confirmed Tuesday that a security flaw in Android 16 can let Gemini actions on the lock screen skip PIN verification and said it is preparing a software update to roll out this week.
  • Researchers and reports describe a specific sequence where pressing Gemini’s “Add attachment” and “Continue” buttons at the same moment from the lock screen can send messages and reactivate app access without a PIN.
  • The exploit needs physical access to the phone to work and reproduces differently across models and makers, with reports saying it affects more than just Pixel devices and that some Samsung users could not reproduce it.
  • Until Google’s patch arrives users can reduce risk by turning off Gemini’s “Make calls and send messages without unlocking” setting and by keeping phones secured when unattended.
  • This bug echoes similar Gemini lock-screen bypasses first reported in September 2025 and highlights a broader tradeoff between convenience shortcuts on the lock screen and strict device authentication.