One WhatsApp Video Call Could Expose Every Photo on Your Locked Android
On some Android phones, a person holding the locked device can answer an incoming WhatsApp video call, open Meta AI’s photo editor and browse the gallery without entering a PIN or passing a biometric check. The reported WhatsApp Android lock screen flaw turns ordinary call controls into a route around the device’s most visible privacy boundary.
The route uses ordinary controls already visible inside WhatsApp. There is no malware to install, no memory-corruption exploit and no need to defeat WhatsApp’s encryption. The phone is locked, but the live call interface remains trusted enough to reach a second feature that was never supposed to expose private files from that state.
Security researcher Jose Rodriguez published the demonstration on 1 September 2026 and said he had reported the issue to Meta and Google. Independent testing by Notebookcheck reproduced it on a Pixel 6 Pro running Android 17 and an Oppo K13 running Android 16 with ColorOS 16. A Samsung Galaxy S25 Ultra running Android 16 with One UI 8.5 correctly demanded authentication, which means the exposure is serious but not universal.
The attack begins with an allowed call
Incoming calls are one of the deliberate exceptions to a mobile lock screen. A user should be able to answer without entering a passcode because the call may be urgent and the caller should not gain access to the rest of the device.
The reported WhatsApp path crosses that line in several ordinary steps:
- The attacker has physical access to a locked Android phone and knows its WhatsApp number.
- A WhatsApp video call is placed to the device and answered from the lock screen.
- The person holding the phone opens the call’s effects menu and switches to backgrounds.
- They select Create with Meta AI, choose to edit an existing photo and reach the gallery.
- On affected devices, WhatsApp displays photos without requesting the device PIN, pattern or biometric authentication.
This is not a remote attack in which a caller can browse photos from elsewhere. Someone must possess the phone and operate its screen. That prerequisite narrows the threat model, but it does not make the failure trivial. A coercive partner, colleague, border official, thief or anyone given brief access to a locked device may have exactly the access needed.
Meta AI turned a cosmetic feature into a bridge
The lock-screen call interface needs access to the camera, microphone and a limited set of call controls. A background effect is a reasonable part of that interface. Opening an editor for existing photographs is a different capability.
The failure appears when those capabilities are composed. WhatsApp’s call screen is allowed to remain interactive while the phone is locked. The Meta AI background tool then offers a route into photo editing. If WhatsApp already has broad permission to read the photo library, the picker can display material that the lock screen should still protect.
No single feature looks extraordinary when considered in isolation. Answering a call, changing a background, editing a photo and granting an app access to media are all legitimate actions. The security failure exists in the path between them.
That is the important design lesson. Mobile platforms do not protect a locked device merely by checking whether each component has permission. They must preserve the locked state as a constraint when one trusted interface launches another.
The result changes by device and permission model
Notebookcheck’s results show why this should not be described as a flaw affecting every Android phone in the same way. Its Pixel 6 Pro and Oppo K13 exposed the gallery, while the Samsung Galaxy S25 Ultra returned to the lock screen and required authentication.
The two Android 16 results also differed, so the operating-system version alone does not explain the outcome. WhatsApp’s build, the manufacturer’s lock-screen implementation, the media picker and the permissions already granted to the app may all influence whether the path succeeds.
The publication also found that this specific route did not work on iPhone. Apple uses its CallKit interface for incoming WhatsApp calls on a locked device, which prevents the caller-facing screen from reaching WhatsApp’s background editor before the phone is unlocked.
These differences are not evidence that one entire platform is secure and another is not. They show that the same application feature can cross different trust boundaries depending on how the operating system and manufacturer contain it.
Full photo access increases the consequence
Android provides a system photo picker that can grant an app temporary access only to media selected by the user. Google describes that picker as the safer alternative to giving an application access to the entire library.
Community testing and Lukas Stefanko’s warning indicate that changing WhatsApp from full photo access to selected-photo access can force a more restricted picker and block this route on affected devices. That is a sensible temporary mitigation, but it is not a substitute for a vendor fix and should not be treated as proof that every phone is protected.
Users can review the setting under Settings > Apps > WhatsApp > Permissions > Photos and videos. Labels differ by Android version and manufacturer. Choose selected photos, limited access or the narrowest option that still supports the way you use WhatsApp.
WhatsApp’s own app lock is useful for protecting chats, but the company says calls can still be answered while the app is locked. It should therefore not be assumed to close a path that begins with an incoming call.
What users and administrators should do now
- Reduce WhatsApp’s photo permission. Prefer selected-photo or limited access instead of full-library access where the device offers it.
- Test the actual device. Lock a managed test phone, place a WhatsApp video call and check whether the background editor can reach media without authentication. Do not assume one Android model represents another.
- Keep WhatsApp and Android current. A fix may arrive through the app, the operating system or an OEM security update.
- Silence unknown callers where appropriate. This reduces nuisance calls, although it does not necessarily prevent a known number from creating the same physical-access opportunity.
- Treat unattended phones as exposed. A lock screen reduces risk, but it cannot compensate for every trusted interface that remains reachable while the device is locked.
- Include intimate-partner and insider scenarios in mobile threat modelling. The most realistic attacker here is not across the internet. It is someone close enough to hold the device.
There is no public fix or exploitation claim yet
At the time of writing, WhatsApp’s public security-advisory page did not list a matching issue or CVE. Rodriguez said the behavior had been reported to Meta and Google, but BlackTree found no public acknowledgement from either company and no confirmed patch guidance.
There is also no public evidence that criminals or commercial spyware operators have used the technique. The demonstrated conditions are specific: physical possession of the phone, the ability to receive and answer a WhatsApp video call, a susceptible device configuration and enough photo permission for the gallery to become useful.
Those limits should shape the response, not erase it. The most sensitive photographs on a phone may concern family, identity documents, medical information, travel, finances or work. A few minutes of physical access can be enough to turn an apparently locked device into a source of highly personal intelligence.
The core problem is not that WhatsApp can edit a background. It is that a feature added for a live call inherited access that no one re-evaluated against the lock screen. The device remained locked. The trust chain did not.
Sources and further reading
- Jose Rodriguez’s original demonstration on X, published 1 September 2026 at 12:11 CEST.
- Lukas Stefanko’s warning and limited-photo-access mitigation, published 2 September 2026.
- Notebookcheck’s independent device testing, published 2 September 2026 at 04:56; the page does not identify a timezone.
- Android Developers: Photo picker, last updated 26 August 2026 UTC.
- Google Android Help: Change app permissions, accessed 2 September 2026.
- WhatsApp Security Advisories, checked 2 September 2026.
- WhatsApp security guidance and app-lock limitations, accessed 2 September 2026.
Related BlackTree analysis: The PDF Extension Could Read WhatsApp. The Browser’s Same-Origin Wall Did Not Apply. and The Phone Was Stolen. An AI Voice Agent Asked the Owner to Unlock It.


