Ready to play
Ready to play
A technical report has revealed a security vulnerability in the "Giminez" AI assistant on Android 16 systems, allowing individuals with the phone to send text messages and WhatsApp messages directly from the lock screen without needing to enter a PIN code or unlock the device. The developer company, Google, has issued a security update to address the flaw, which is expected to reach affected devices within a few days. The vulnerability occurs when the Giminez app's access to the messaging application is revoked; an attacker can press the Continue and Add Attachment buttons simultaneously to bypass security and send messages without verifying the user's identity. Additionally, they can re-link WhatsApp to Giminez by typing @WhatsApp into the input field—even if it wasn't previously connected—without needing to enter the lock code. The requirement for direct access to the device reduces the severity of the vulnerability compared to remote attacks. However, it could be exploited in cases of phone theft to send fraudulent messages or impersonate the owner before retrieving or locking the device. The issue affects all Android devices running the impacted version, though Google has not yet confirmed which specific models are vulnerable. Users are advised to temporarily disable the Giminez feature on the lock screen to protect themselves.
Notice: This Is an AI-Generated Summary
Comments (0)