WhatsApp Android Flaw Allows Access to Private Photos via Lock Screen
- A newly discovered security flaw in WhatsApp for Android allows unauthorized users to access private photo libraries on locked smartphones during incoming video calls, according to recent security...
- The security issue was first publicized by researcher Jose Rodriguez on the social media platform X, and has since been confirmed by Meta, according to reporting by heise.de.
- Testing across different hardware configurations shows that the vulnerability does not impact all Android devices equally.
A newly discovered security flaw in WhatsApp for Android allows unauthorized users to access private photo libraries on locked smartphones during incoming video calls, according to recent security disclosures. The vulnerability bypasses the lock screen without requiring a password or biometric verification, exposing personal media on specific device models.
How the WhatsApp Lock Screen Vulnerability Works
The security issue was first publicized by researcher Jose Rodriguez on the social media platform X, and has since been confirmed by Meta, according to reporting by heise.de. The flaw does not require a remote network attack or technical exploits. Instead, physical access to the device is necessary while an incoming WhatsApp video call arrives on a locked Android smartphone. According to testing details published by notebookcheck.com, an individual holding a locked phone can swipe to accept the incoming video call. Once the video connection is active, tapping the effects icon opens a menu containing tabs for effects, filters, and backgrounds. Switching to the background section reveals a button labeled Create with Meta AI. Selecting options to edit an existing photo bypasses standard lock screen security controls and opens the device’s complete photo gallery directly.
https://x.com/VBarraquito/status/2094729843761922276
Device Variations and Manufacturer Implementations
Testing across different hardware configurations shows that the vulnerability does not impact all Android devices equally. Notebookcheck.com reported testing a Pixel 6 Pro running Android 17 with the latest security patch, which allowed unrestricted access to personal images without authentication. An Oppo K13 running ColorOS 16 exhibited the same bypass behavior. In contrast, testing on a Samsung Galaxy S25 Ultra running One UI 8.5 successfully blocked the unauthorized access attempt. According to notebookcheck.com, tapping the Meta AI button on the Samsung device immediately redirected the user back to the lock screen, where a password or biometric verification was required. This discrepancy indicates that the flaw depends heavily on how individual hardware manufacturers implement custom Android interfaces and lock screen permission boundaries. Apple devices remain unaffected by the issue. According to heise.de, Apple’s CallKit framework forces WhatsApp to utilize the native iOS calling interface, preventing third-party screen bypasses of this nature.

Scope of Access and Mitigation Steps
While the exploit grants viewing access to stored media, it does not provide full device control. Meta has confirmed that a fix is currently being distributed, as reported by heise.de. While users await the permanent patch, a temporary workaround is available through app permission settings. Users can restrict WhatsApp’s photo access by navigating to App Info, selecting Permissions, and choosing the option to allow restricted access, which limits the specific photos and videos the application can read.

