في صدمة أمنية جديدة لمستخدمي نظام «أندرويد»، كُشف النقاب عن ثغرة برمجية خطيرة في تطبيق الذكاء الاصطناعي «جيميناي» التابع لشركة «قوقل»، تتيح لأي شخص يحمل الهاتف تجاوز شاشة القفل والوصول إلى وظائف الجهاز الرئيسية وإجراء المكالمات وإرسال الرسائل، دون الحاجة لمعرفة الرمز السري أو بصمة الوجه.
المعطيات التي كشف عنها تقرير لموقع «ذا ريجستر» التقني البريطاني، أظهرت أن الخلل يمنح المهاجم صلاحيات واسعة تجعل الهاتف المفتاح المفتوح للجميع في حالات السرقة أو فقدان الجهاز.
وأوضح التقرير تفاصيل الآلية التي استغل بها المستخدمون هذا الخلل في نظام أندرويد 16 الجديد:
- تجاوز الرمز السري: بالوضع الطبيعي، يطلب التطبيق كلمة المرور عند محاولة الوصول لأي بيانات حساسة من شاشة القفل، إلا أن الثغرة سمحت لـ«جيميناي» بتجاوز نظام الحماية تلقائياً.
- الاستيلاء على الوظائف الأساسية: أتاحت الثغرة إمكانية إجراء المكالمات الهاتفية، وإرسال الرسائل النصية القصيرة (SMS)، بل وحتى بعث رسائل عبر تطبيق «واتساب» مباشرة والهاتف مغلق تماماً.
- زر الاستمرار وإشارة (+): تبدأ الثغرة بالظهور بمجرد الضغط على زر الاستمرار مع إشارة (+) التي تظهر بجانب عبارة «اسأل جيميناي» على شاشة القفل، ليقوم المساعد بفتح الصلاحيات دون التحقق من هوية صاحب الهاتف.
هل الخطر حقيقي؟
ورغم أن استغلال الثغرة يتطلب حيازة فيزيائية للهاتف واستغراق بعض الوقت لتفعيلها (مما يعني عدم إمكانية تنفيذها عن بُعد)، إلا أن الخبراء في موقع «ديجيتال تريندز» يرون أن خطورتها تتضاعف في حالات سرقة الهواتف المحمولة.
وتكمن الخطورة الأكبر في التوجه الحالي لشركة قوقل نحو تحويل «جيميناي» إلى وكيل ذكاء اصطناعي (AI Agent) يملك صلاحيات شاملة للوصول إلى كافة الصور، والملفات، والتطبيقات الشخصية؛ مما يعني أن أي ثغرة مماثلة مستقبلاً قد تفتح الباب أمام تسريب بيانات الهاتف بالكامل.
وأمام هذه التقارير، سارعت شركة «قوقل» بالرد عبر متحدث رسمي أقرّ بوجود الثغرة، مؤكداً أن العمل جارٍ على إطلاق تحديث أمني هوائي (OTA) خلال هذا الأسبوع لإصلاح الخلل على كافة الهواتف المتأثرة.
وفي المقابل، ينصح الخبراء التقنيون بإلغاء إذن ظهور تطبيق «جيميناي» على شاشة القفل كلياً من إعدادات الهاتف بشكل مؤقت، وذلك لتفادي أي استغلال للثغرة في حال فقدان الجهاز أو سرقته حتى يتم تثبيت التحديث الأمني الجديد.
In a new security shock for users of the "Android" system, a serious software vulnerability has been revealed in the artificial intelligence application "Gemini" owned by "Google," allowing anyone with the phone to bypass the lock screen and access the device's main functions, make calls, and send messages, without needing to know the passcode or facial recognition.
The data revealed by a report from the British tech site "The Register" showed that the flaw grants attackers broad permissions, making the phone an open key for everyone in cases of theft or loss of the device.
The report detailed how users exploited this flaw in the new Android 16 system:
- Bypassing the passcode: Normally, the application requests a password when attempting to access any sensitive data from the lock screen, but the vulnerability allowed "Gemini" to bypass the security system automatically.
- Seizing core functions: The flaw enabled the ability to make phone calls, send text messages (SMS), and even send messages via the "WhatsApp" application directly while the phone is completely locked.
- The continue button and the (+) sign: The vulnerability begins to appear as soon as the continue button is pressed along with the (+) sign that appears next to the phrase "Ask Gemini" on the lock screen, allowing the assistant to open permissions without verifying the identity of the phone owner.
Is the danger real?
Although exploiting the vulnerability requires physical possession of the phone and takes some time to activate (which means it cannot be executed remotely), experts at "Digital Trends" believe that its danger multiplies in cases of mobile phone theft.
The greater danger lies in Google's current direction to transform "Gemini" into an AI Agent with comprehensive permissions to access all photos, files, and personal applications; meaning that any similar vulnerability in the future could open the door to leaking the entire phone's data.
In response to these reports, "Google" quickly replied through an official spokesperson who acknowledged the existence of the vulnerability, confirming that work is underway to release an over-the-air (OTA) security update this week to fix the flaw on all affected phones.
Meanwhile, tech experts advise temporarily revoking the permission for the "Gemini" application to appear on the lock screen from the phone's settings, in order to avoid any exploitation of the vulnerability in case the device is lost or stolen until the new security update is installed.