Android Vulnerability Allows Unauthorized SMS Sending via Gemini App
A security vulnerability has been identified in Android devices, allowing the Gemini app to send SMS messages without user verification. This issue, known as an authentication bypass vulnerability, occurs when a user disables Gemini's access to certain apps like Messages. If someone with physical access to the device attempts to use Gemini from the lock screen to send a message, the phone typically requests a PIN. However, by pressing the 'Add attachment' button simultaneously with the 'Continue' button, the PIN requirement is bypassed. This flaw not only permits unauthorized SMS sending but also enables reactivation of access to apps like WhatsApp, even if previously disabled. The vulnerability has been reported since May on Android 16 and is acknowledged by Google, which is working on a fix. The issue affects more than just Pixel devices, though the full scope of affected Android versions is unclear.