Google Gemini Bug Could Let Hackers Access WhatsApp on Locked Android Phones

Google is working on a security fix for an Android lock screen vulnerability that could allow attackers to access messaging applications, including WhatsApp, through Gemini without entering the device PIN. The issue has raised concerns among Android users because it could potentially expose private conversations if an attacker gains physical access to a locked smartphone.

The vulnerability affects certain Android 16 devices where Gemini is enabled to operate from the lock screen. According to reports, an attacker does not need to unlock the device manually to exploit the issue, but they must have physical possession of the phone.

Security researchers found that the flaw could allow unauthorized users to perform actions that normally require device access. In some cases, attackers may be able to send SMS or WhatsApp messages while making them appear as if they were sent by the legitimate device owner.

The issue highlights the growing complexity of artificial intelligence assistants integrated into smartphones. While AI tools like Gemini are designed to provide convenience by helping users perform tasks quickly, their access to device features must be carefully managed to prevent security risks.

Google has acknowledged the problem and is reportedly working on a solution to address the vulnerability. Until an official fix becomes widely available, Android users are advised to review their lock screen assistant settings and limit the actions AI assistants can perform when the device is locked.

Experts recommend disabling sensitive lock screen actions for AI assistants, especially features that allow access to messaging, calls, or other personal information. Users should also ensure their devices are updated with the latest Android security patches once they become available.

The vulnerability is another example of how cybersecurity challenges are evolving as artificial intelligence becomes more deeply integrated into mobile operating systems. Traditional security measures, such as PIN codes and biometric authentication, may need additional safeguards as AI-powered tools gain more control over device functions.

Messaging applications such as WhatsApp contain highly personal information, including private conversations, media files, and account details. Unauthorized access to these platforms can create risks ranging from privacy violations to identity misuse.

Android users should remain cautious about granting extensive permissions to AI assistants and regularly check application access settings. Monitoring security updates from Google and smartphone manufacturers will also be important in protecting devices against emerging threats.

As Google continues developing a fix, the incident serves as a reminder that convenience features must be balanced with strong privacy protections. Users are encouraged to maintain updated software and review device settings to reduce potential security risks.