< Back to situation

[REVISION HISTORY]

WhatsApp Android security vulnerability

Updated 1 time since CLSTR started tracking revisions of this situation.

What changed

2026-09-06 07:45 UTC → 2026-09-06 19:02 UTC · added removed

A security vulnerability has been identified in WhatsApp for Android that allows unauthorized access to a device’s photo gallery while the phone remains locked. The flaw is linked to the video call interface; when a call is answered from the lock screen, a user can navigate to the effects or backgrounds menu and use Meta AI functions to trigger the local photo gallery, bypassing the need for a PIN, password, or biometric authentication. The vulnerability affects various manufacturers, including Google Pixel, OPPO, Pixel and vivo, OPPO, but does not appear to impact Samsung Galaxy devices, which maintain security prompts. iOS users are unaffected due to native system protocols. Both WhatsApp and Google have been notified, with Security researcher Jose Rodriguez identified the flaw, noting that while an attacker cannot send or open specific files through this view, they can see thumbnails of private photos, which could be photographed by an external camera. Meta has reportedly released a security patch expected to address the issue. issue, and users are advised to update their WhatsApp application immediately.

Versions

  1. 2026-09-06 19:02 UTC WhatsApp Android security vulnerability
  2. 2026-09-06 07:45 UTC WhatsApp Android security vulnerability

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.