Android lockscreen vulnerabilities have once again made headlines, this time with a peculiar exploit involving the Gemini app. This exploit allows users to bypass the lockscreen PIN requirement and send SMS messages without verification, even when the app's access has been disabled. The issue lies in a seemingly innocuous interaction between the user interface and the underlying system, where pressing the 'Add attachment' button simultaneously with the 'Continue' button circumvents the security measure. This exploit is not limited to SMS messages; it also grants access to other apps, such as WhatsApp, which had been previously restricted in the Gemini settings. The vulnerability has been reported since May on Android 16 and is reportedly known by Google, with a fix already in the works. It affects not only Pixel devices but also other Android flavors, although specific details are still lacking. This incident highlights the ongoing challenge of securing complex software systems, especially those with special privileges like Gemini's ability to run from the lock screen. It also underscores the importance of user interface design in security, as subtle interactions can have significant security implications. The exploit's discovery and Google's swift response demonstrate the importance of proactive security measures and the need for continuous vigilance in the face of evolving threats.