A vulnerability has been discovered in the WhatsApp app for Android that allows access to personal photos on the device without unlocking the device. This is reported by the resource 9 to 5 google and association To the user who first noticed this, the information was later corroborated by many other sources.
Photo credit: Gilles Lambert/Unsplash
Here’s how it works: When a WhatsApp call comes in, you don’t need to unlock your phone to answer it. At this point the user can click the filter or AI tool button in Meta✴ For photo editing. Next, instead of blocking access to the photos on the owner’s device, the system will show a preview of the photo without requiring a PIN or biometric verification.
This issue does not affect all devices. It turns out that on Galaxy smartphones, you’ll be asked to unlock the screen, while on Pixel and Oppo devices, the protection can be bypassed entirely. Since WhatsApp uses the secure standard iOS calling interface, this vulnerability was not found on the iPhone.
At the same time, as the source points out, a complete bypass of the Lock screen won’t happen, and access to the rest of the device remains closed. Additionally, the photos cannot be edited or deleted, although an attacker could theoretically use the device to capture the photos.
Information about the vulnerability has been transmitted to WhatsApp developers and Google, but a solution to the problem has not yet been announced. As a temporary measure, it is recommended to restrict WhatsApp’s access to photos and videos in Android permission settings.
If you find an error, select it with your mouse and press CTRL+ENTER.










