This shows particularly poor design by Google. There are a number of ways that mobile devices can be compromised and Google cannot account for all of them, but this is the most basic level.
If you're trying to protect an application from a device that's been stolen, assume that the attacker has unlocked, physical access. The only platform that has a claim to a safe lock-screen is Blackberry because they: - Require the password before allowing any USB access - Will wipe the device after 5 failed password entries by USB or on the console