< Back to all clusters
[TECHNOLOGY] · United States · 12 sources

started · updated

WhatsApp security flaw allows Android photo access while locked

A security vulnerability in WhatsApp for Android allows unauthorized access to a device's photo gallery while the phone is still locked. Discovered by security researcher Jose Rodriguez, the flaw can be exploited by someone with physical access to the device.

The exploit occurs when a user receives a WhatsApp video call and answers it directly from the lock screen. Once the call interface is active, a person can navigate to the effects menu and select the ‘Create with Meta AI’ option. Choosing to edit an existing photo can trigger the device to open the local photo gallery without requiring a PIN, password, or biometric authentication.

The impact varies by manufacturer. Testing indicates that Google Pixel and OPPO devices are susceptible to this bypass. However, Samsung devices using One UI appear to be protected, as they prompt for authentication before granting access to the gallery. iOS users are unaffected because Apple requires WhatsApp to use the native iOS calling interface, which maintains system security protocols.

Entities

Android · Google · José Rodríguez · Meta · Oppo · WhatsApp