A serious vulnerability has been discovered in WhatsApp for Android that enables anyone holding a locked phone to access its entire photo gallery—without entering any authentication. A security researcher identified the exploit, which has been reported to Meta and Google, but no patch is yet available.
How the Bypass Works
The flaw is triggered when a locked Android device receives a WhatsApp video call. Once the call is answered, the attacker taps the effects icon—typically used for filters and backgrounds—and switches to the “backgrounds” tab. From there, by choosing “Create with Meta AI” followed by “Edit photo,” the user can navigate straight into the full gallery without needing the lock screen PIN, password, or fingerprint. The exploit requires physical access to the device, but no hacking skill or specialized tools.
Which Devices Are Affected—and Which Aren’t
This issue isn’t uniform across all Android phones. Devices such as the Google Pixel 6 Pro and Oppo K13 have been shown to be vulnerable—these phones allow access to all stored photos using the Meta AI photo tool when the exploit is executed. Conversely, some models like the Samsung Galaxy S25 Ultra (with One UI) correctly prevent access by reverting to the lock screen and requiring authentication.
iPhones are not impacted by this bug. On iOS, WhatsApp calls are handled through Apple’s native CallKit framework, which forces incoming calls through the standard call interface and prevents access to app-specific menus that could lead to the lock screen bypass vulnerability.
Temporary Safeguards Until a Fix Arrives
While Meta and Google haven’t issued a fix yet, there is a workaround. Android users can go into the app permissions for WhatsApp and change its photos and videos permission to “Allow limited access” instead of full gallery access. This limits the images WhatsApp can reach, thereby closing the loophole exploited by this vulnerability.
WhatsApp has over two billion users globally, making this flaw particularly concerning. It highlights a recurring issue in smartphone security: when apps add convenience features—like in-call effects and background tools—those layers can inadvertently undermine core protections like the lock screen. The threat is especially high in relationships or shared environments where someone may gain temporary access to a locked device.
If you’re using a vulnerable Android device, updating app permissions now is essential. Keep watch for an official patch from Meta or Google to fully secure your photos.
This bug is more than just an annoyance—it shows just how thin the line can be between usability and safety. WhatsApp must act quickly to guard against this exposure, and users should double-check permissions on Android phones. The broader lesson: every feature that touches lock-screen behavior deserves scrutiny, especially when AI tools are involved.