Cyber Security News

Researchers Bypassed Android Lock Screen using Driving mode Assistant

Recent reports indicate that researchers have discovered a new method to bypass the Android Lock Screen and extract sensitive information like photos, contacts, browsing history, shared location, and much more.

This issue existed on the most recent versions of Android, such as Android 14 and 13. Moreover, Google has reported this issue, and a security patch is yet to be provided for the affected versions.

Android Lock Screen Bypass

A researcher named Jose Rodriguez asked a question about accessing Google Maps links from the lock screen. The question was posted on multiple platforms, including Twitter, Reddit, and Telegram, and it was stated that his Google Pixel was locked.

However, he found a method to bypass the lock screen and also mentioned that Google has been aware of this issue for at least six months. The video provided by the researchers involves very simple actions with which an Android device can be successfully bypassed to the main screen.

The exploit has been differentiated with two perspectives DRIVING MODE enabled and DRIVING MODE disabled. 

Exploitation POC

According to the video, the researcher used Google Assistant initially for the interpreter mode. With this mode, users can translate their own language into English.

Additionally, it also offers a keyboard for users to type their language. Android also has a feature to detect links and navigate to specific applications with “highlighted text.” The researcher used the keyboard to type a Google Maps link and select all the text.

Once the text is highlighted, Android’s link discovery feature kicks in and detects the navigation for Google Maps. Once the user clicks on the map icon above the highlighted text, the user is taken to Google Maps after some additional steps, and the Android lock screen is successfully bypassed.

If the DRIVING MODE is disabled, a threat actor can use this technique to access recent and favorite locations and contacts and share locations in real time with contacts or with an email that the attacker can enter manually.

If the DRIVING MODE is enabled, a threat actor can combine it with another exploit and gain full control over the Android device and the user’s Google account. The threat actor will need physical access to the victim’s device as a prerequisite.

Users of Android with versions 13 and 14 are recommended to keep their devices secured with additional lock restrictions and do not lose their phone’s physical access.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago