WhatsApp Android Bug Allows Access to Photos Without Unlocking Phone
- A newly discovered security vulnerability in WhatsApp for Android lets users bypass the lock screen and access a device's photo gallery during an incoming video call, according to...
- The exploit does not require specialized hacking tools, malicious applications, or deep technical knowledge, according to reporting by La Razón.
- Independent testing by security researchers reveals that the flaw does not affect all Android devices uniformly.
A newly discovered security vulnerability in WhatsApp for Android lets users bypass the lock screen and access a device’s photo gallery during an incoming video call, according to security reports published on September 1 and September 2, 2026. The issue, which requires physical access to a target phone, was uncovered by security researcher José Rodríguez and has been reported to Meta and Google, as noted by RedesZone and La Razón.
How the WhatsApp Lock Screen Flaw Works
The exploit does not require specialized hacking tools, malicious applications, or deep technical knowledge, according to reporting by La Razón. An attacker with physical possession of a locked phone simply needs to call the device via WhatsApp video. When the victim’s phone rings, the user can answer the incoming call directly from the locked screen interface without entering a PIN, password, or biometric verification like a fingerprint or facial scan. Once the video call connects, the person holding the device can tap the effects icon on the screen, which opens a tabbed menu containing filters, backgrounds, and visual tools. Selecting the background tab reveals an option labeled Create with Meta AI, followed by an Edit photo setting. According to RedesZone, selecting this prompt bypasses the device’s lock screen entirely, opening the full local photo gallery instead of demanding security credentials. Security researcher José Rodríguez demonstrated the procedure in a video posted to his account on the social network X, noting that the technique leaves no digital traces or evidence of unauthorized access behind.
Be aware that your photos can be accessed without unlocking your phone when you receive a WhatsApp video call on Android.
This is in plain sight.
It’s not hidden, not a secret feature.
Not a hack.
This has already been reported to Meta and Google.
https://x.com/VBarraquito/status/2094729843761922276
Device Vulnerability and Manufacturer Differences
Independent testing by security researchers reveals that the flaw does not affect all Android devices uniformly. According to tests cited by RedesZone and La Razón, a Google Pixel 6 Pro running Android 17 and an Oppo K13 running ColorOS 16 proved vulnerable, allowing open access to stored images during a simulated call test. By contrast, tests conducted on a Samsung Galaxy S25 Ultra running Android 16 and One UI 8.5 showed that the device behaved securely. When testers attempted to access Meta AI from the incoming video call interface on the Samsung hardware, the operating system forced the user back to the lock screen and demanded proper authentication. This variation indicates that the exploit depends heavily on how individual hardware manufacturers configure lock screen permissions rather than a uniform flaw across the entire Android operating system. Apple devices remain unaffected by the issue; according to La Razón, iOS uses CallKit to route incoming application calls through the native Apple call interface, preventing third-party apps like WhatsApp from exposing full menu layers while the handset remains locked.
Temporary Mitigations and Industry Response
As of September 2, 2026, Meta has not issued an official public statement or released a software patch to correct the vulnerability, according to RedesZone. Until an official update becomes available, security analysts recommend adjusting application permissions directly within Android settings. Users can navigate to the application permission configuration for WhatsApp, select permissions for photos and videos, and restrict access from full library sharing to a limited selection. This adjustment ensures that even if the vulnerability is triggered, the application can only display a pre-approved subset of images rather than the entire device photo repository.

