VYPR
researchPublished Sep 2, 2026· 1 source

WhatsApp Video Call Flaw Exposes Android Photo Galleries

A newly discovered WhatsApp vulnerability on Android allows unauthorized access to a device's photo gallery by exploiting the 'Create with Meta AI' feature during a video call.

A critical privacy vulnerability has been identified in WhatsApp for Android, enabling unauthorized access to a device's entire photo gallery through a seemingly innocuous video call. Security researcher Jose Rodriguez, known for uncovering similar lock screen bypasses, reported the flaw to Meta and Google. The exploit requires physical access to the target device but no advanced technical skills.

The attack vector involves answering an incoming WhatsApp video call on a locked Android phone. Once the call is active, users can navigate to the effects menu, select backgrounds, and then choose the "Create with Meta AI" option. Following this, selecting "Edit photo" bypasses the device's lock screen, granting full access to the photo gallery without requiring a PIN, password, or fingerprint.

This vulnerability poses a significant risk, particularly as a potential tool for stalkerware. Individuals with malicious intent, such as abusive partners or ex-partners, could exploit an unattended, locked phone to silently browse private images. The exploit is particularly insidious because it leaves minimal traces and mimics normal application behavior, making it difficult for victims to detect unauthorized access to their photos.

Testing has revealed that the vulnerability's prevalence varies across Android devices and manufacturer customizations. While devices like the Google Pixel 6 Pro and Oppo K13 were found to be susceptible, a Samsung Galaxy S25 Ultra running One UI reportedly blocked the exploit, redirecting the user back to the lock screen. iPhones are unaffected due to Apple's CallKit framework, which routes WhatsApp calls through the native iOS interface, preventing access to WhatsApp's custom in-call menus.

Until Meta releases a patch, users can implement a workaround by adjusting WhatsApp's app permissions. By navigating to the phone's settings, selecting WhatsApp, and changing the photos and videos permission to "Allow limited access," users can restrict the app's access to only a pre-approved subset of images, thereby closing the loophole. This mitigation prevents the app from accessing the entire gallery.

Given WhatsApp's massive user base, exceeding two billion users globally, this flaw highlights a recurring security concern: the potential for convenience features integrated into lock screens to inadvertently create bypasses. Features like call previews and quick-reply options can sometimes be exploited.

Users, especially those concerned about potential device surveillance within personal relationships or households, are advised to apply the permission workaround immediately. Staying vigilant for an official security update from Meta is also crucial to fully resolve the vulnerability.

Synthesized by Vypr AI