CyberSecurityNews

WhatsApp Video Call Flaw Lets Anyone Bypass Your Android Lock Screen and View Your Photos


A newly disclosed WhatsApp flaw on Android is raising fresh privacy alarms, allowing anyone holding a locked phone to browse through its entire photo gallery simply by answering an incoming video call.

The issue was uncovered by security researcher Jose Rodriguez, known for a string of past lock screen bypass discoveries on both Android and iOS, and has already been reported to Meta and Google.

As of now, no patch has been released, leaving the flaw actively exploitable in the wild. The attack requires physical access to the target device but demands no hacking skill or special tools. When a locked Android phone receives a WhatsApp video call, the person holding it can simply swipe to answer.

Once the call connects, tapping the effects icon opens a menu with tabs for effects, filters, and backgrounds.

Switching to the backgrounds tab and selecting “Create with Meta AI,” followed by “Edit photo,” bypasses the lock screen entirely and pulls up the device’s full photo gallery, no PIN, password, or fingerprint required.

What makes this bug especially dangerous is its potential for abuse as a stalkerware technique . An abusive partner, jealous ex, or anyone who simply knows a target’s WhatsApp number could exploit an unattended, locked phone left on a table or charging station to silently browse private images.

Because the exploit leaves virtually no trace and mimics normal app behavior, victims may have no idea their personal photos were ever viewed.

Device / Operating SystemBehavior During In-Call ExploitVulnerability Status
Google Pixel 6 ProBypasses lock screen and opens complete photo galleryVulnerable
Oppo K13Exposes device storage images through Meta AI photo toolVulnerable
Samsung Galaxy S25 Ultra (One UI)Redirects user to lock screen and demands authenticationProtected
Apple iPhone (iOS)Routes call via native CallKit; blocks in-call custom menusNot Affected

Testing documented in demonstrations shared by Lukáš Štefanko shows the vulnerability is not universal across the Android ecosystem.

Devices such as the Google Pixel 6 Pro and Oppo K13 were found susceptible, while a Samsung Galaxy S25 Ultra running One UI correctly threw the exploit back to the lock screen, demanding authentication before proceeding.

This suggests the flaw stems from how individual manufacturers customize lock screen permissions rather than an issue baked into core Android.

iPhones are unaffected altogether, since Apple’s CallKit framework forces incoming WhatsApp calls through the native iOS calling interface, blocking access to WhatsApp’s custom in-call menus and, by extension, the background-replacement tool that enables the bypass. Until Meta ships a fix, users concerned about this exposure have one practical workaround.

Navigating to the phone’s app permissions settings, selecting WhatsApp, and restricting its photos and videos permission to “Allow limited access” rather than full gallery access effectively closes the loophole, since the app can then only reach a pre-approved subset of images rather than the entire library.

Given WhatsApp’s status as one of the most widely used messaging platforms globally, with over two billion users, this flaw underscores a recurring theme in mobile security: convenience features layered on top of lock screens, from call previews to quick-reply tools, routinely create unintended pathways around device authentication.

Users, particularly those in relationships or households where device access might be misused for surveillance, should apply the permission fix immediately and stay alert for an official patch from Meta or Google.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.



Source link