A WhatsApp Video Call Can Open Your Photo Gallery Without Unlocking Your Phone
- The Mess: A newly reported WhatsApp privacy flaw can let someone with physical access to certain locked Android phones reach the device’s photo gallery through an incoming WhatsApp video call. No PIN. No fingerprint. No Face Unlock.
- The Damage: A locked phone can still expose private photos to anyone holding the device. The attacker does not need malware, exploit code or access to the rest of the operating system.
- The Fix: Until Meta and Google provide a fix, restrict WhatsApp’s Android photo and video permissions to limited or selected photos and avoid giving the app unrestricted access to your entire gallery.
Your phone is locked.
Your photos should be locked too.
Apparently, that assumption does not always survive a WhatsApp video call.
Security researcher Jose Rodriguez demonstrated a surprisingly simple path that can expose photos stored on certain locked Android phones without requiring the device PIN, password or biometric authentication.
The attacker does not need hacking tools.
They do not need malware.
They do not need to unlock Android.
They just need the phone in their hands.
The reported bypass starts with an incoming WhatsApp video call.
Android normally allows calls to be answered from the lock screen. That part is expected.
The problem begins after the call connects.
On affected devices, the person holding the phone can access WhatsApp’s video-call effects, open the backgrounds section and reach Meta AI’s image functionality. From there, the option to edit an existing photo can expose the device’s photo gallery before Android requests authentication.
That is where the lock screen stops doing its job.
The phone itself remains locked.
The attacker cannot suddenly browse through every application, change system settings or take control of the entire device.
But they may be able to view the photos stored in the gallery.
And for many users, that is already bad enough.
Private photos.
Personal documents saved as screenshots.
Pictures of IDs.
Family images.
Medical information.
Passwords accidentally captured in screenshots.
A lock screen bypass does not need to provide full device compromise to become a serious privacy problem.
There is an important detail, though.
The issue does not appear to affect every Android phone.
Testing reported so far suggests that the behavior depends partly on the device manufacturer and how the Android lock screen interacts with applications and media access.
A Google Pixel 6 Pro and an OPPO K13 were reported as vulnerable during testing.
A Samsung Galaxy S25 Ultra, however, reportedly stopped the sequence and required the user to authenticate before continuing.
That makes this situation more interesting than a simple “WhatsApp vulnerability affects every Android device” headline.
The same Android version does not necessarily mean the same lock-screen behavior.
The security boundary can also depend on the software layer added by the phone manufacturer.
Apple’s iPhone does not appear to be affected by this specific issue.
WhatsApp calls on iOS are handled through Apple’s native CallKit framework, which prevents WhatsApp from exposing its own full call interface and the same path toward the Meta AI image tools while the phone remains locked.
The reported bypass has already been disclosed to Meta and Google.
As of the latest public reports, however, there is no announced patch.
That leaves users with a temporary workaround.
Android allows users to control which photos and videos an application can access.
If WhatsApp has unrestricted access to the entire gallery, the reported bypass may expose the full collection.
Changing the permission to limited or selected photos reduces what the application can see.
It is not a perfect solution.
It can also reduce some of WhatsApp’s normal media functionality.
But until the lock-screen interaction is fixed, limiting gallery permissions is the obvious defensive move.
There is another uncomfortable lesson here.
The attack surface around a locked phone keeps growing.
Years ago, the lock screen mainly displayed notifications and incoming calls.
Now applications can expose camera features, messaging controls, media functions, AI tools, call effects and other interactive components before the device owner authenticates.
Every additional feature creates another question:
What happens if that feature can reach something it should not?
In this case, an incoming video call appears to become the bridge.
The phone is still technically locked.
The gallery may not be.
Bugstoday’s take: A lock screen is supposed to be a boundary, not a suggestion. This reported WhatsApp bypass does not hand attackers the entire phone, but it does not need to. Private photos are private data. If a video call can expose them before Android asks for authentication, the security model has already failed where users expect it to work most.
Today’s Bugs. Tomorrow’s Breaches.
Technical Sources
- Android Authority — WhatsApp Privacy Flaw Can Expose Photos on Locked Android Phones
- WhatsApp Help Center — AI-Generated Call Backgrounds
- 9to5Google — WhatsApp for Android Loophole Lets Private Photos Be Accessed Without Unlocking
- Security Research by Jose Rodriguez
- Meta and Google — Vulnerability Disclosure Reports




