TechNewsReel
Live

WhatsApp Android flaw lets users browse private photos on locked devices

A security loophole enables anyone with physical access to a locked phone to access the gallery via a video call interface.

TechNewsReel Newsroom · September 2, 2026

A security flaw in WhatsApp for Android allows unauthorized users to view private photos on a locked device without needing a PIN or biometric authentication. The vulnerability turns a standard incoming video call into a gateway for browsing a user's private gallery.

The exploit is triggered when a user answers an incoming WhatsApp video call and navigates to the effects and filters menu. From there, by selecting 'Create with Meta AI' and then 'Edit photo,' the app opens the device's photo gallery, bypassing the system's lockscreen requirements. Reports indicate the loophole allows anyone with physical access to the device to view images simply by placing a call to the phone.

Device-Specific Vulnerabilities

The flaw does not affect all Android hardware equally. Security researchers have confirmed the exploit works on Google Pixel devices, such as the Pixel 6 Pro, and Oppo devices, including the Oppo K13.

However, the vulnerability is not universal. Samsung Galaxy devices, such as the S25 Ultra, block the exploit by demanding a passcode or biometric scan before the gallery can be accessed. Additionally, the flaw is absent on iPhones, as iOS CallKit restrictions prevent the app from bypassing the lockscreen in this manner.

Privacy Implications

While the exploit does not grant full access to the Android operating system or allow for the digital extraction of files, it represents a significant privacy breach. The loophole enables a form of 'shoulder surfing,' where an attacker can browse sensitive visual data or use a second device to take photographs of the screen while the target phone remains locked.

Because the attack requires physical proximity, the risk is highest in scenarios where a device is left unattended in a public space or accessed by an untrusted individual. The ability to bypass biometric security through a third-party app's AI tools highlights a critical gap in how certain Android OEMs handle permission hand-offs during active calls.

What's Next

Users of affected Pixel and Oppo devices are advised to remain vigilant about the physical security of their devices. While some reports suggest restricting WhatsApp's media permissions as a potential mitigation, a formal patch from Meta has not yet been deployed to resolve the loophole. It remains to be seen if other Android manufacturers are similarly vulnerable or if Samsung's implementation is the only effective defense on the platform.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.