16:45
16:31
15:00
10:25
09:50
08:00
16:45
16:31
15:00
10:25
09:50
08:00
16:45
16:31
15:00
10:25
09:50
08:00
16:45
16:31
15:00
10:25
09:50
08:00
A newly discovered privacy flaw in WhatsApp for Android can let someone browse a user’s photos from the lock screen, without entering a PIN or passing biometric authentication, 9to5Google reports.
The workaround relies on an incoming WhatsApp call. If someone answers it on a locked device and opens Meta’s filters or AI effects from the call interface, WhatsApp can bring up the photo picker without first requiring the phone to be unlocked.
The behavior varies by manufacturer. The loophole has been reproduced on Google Pixel and Oppo devices, but Samsung Galaxy phones still prompt for authentication before showing the photo library. iPhones are unaffected because WhatsApp calls are handled through Apple’s native iOS calling interface.
This does not give an attacker unrestricted access to the device or allow them to download the photos directly. It does, however, make images visible on screen, meaning anyone with physical access to the phone could view them and capture copies with another device.
Both WhatsApp and Google have been alerted to the issue, though a patch has yet to be released. For now, Android users can limit the exposure by switching WhatsApp’s photo and video permissions to Restricted access, which lets them choose which images the app is allowed to see.

