
WhatsApp pitches itself as a pretty secure vault, offering end-to-end encryption by default on your messages, calls, media, and photos.
The official WhatsApp site reminds us that "privacy and security is in our DNA," but now, a potentially problematic security flaw has been discovered. It seemingly allows users to access your private camera roll without needing to unlock certain phones.
Locking your smartphone should mean it's secure from prying eyes unless they have your PIN, pattern, or password on Android, but as we've covered about how some bad actors are trying to remotely access our smartphones via scam calls or using disguised charging cables, there are those out there who have pretty advanced ways of snooping where they're not wanted.
Although there are no reports of this current exploit being used for that, it's not hard to see how accessing someone's camera roll without their permission could be seen as a problem.
What is the WhatsApp photo flaw?

Advert
Originally shared on X by Jose Rodriguez, they explain how someone would require physical access to your smartphone but can get inside your camera roll on some Android phones.
The OP initially said: "I would also like to inform all users in a responsible manner so that they protect themselves, because this is a very visible security flaw, very easy to discover, and I am sure that it will be exploited right now."
In a follow-up, they show us how it was relatively easy to pull off. When a locked Android device receives a video call through WhatsApp, it's a simple case of swiping to answer.
Even though this is arguably seen as a benefit instead of having to fiddle around with unlocking your phone, it also appears that it's possible to go deeper into a device by tapping the effects icon and opening a menu for various filters and backgrounds.
Although video calls default to the filters tab, you can switch to the background section and select "Create with Meta AI" to take a new image or edit existing ones while overriding security protocols.
Notebook Check tested the methodology on a Pixel 6 Pro that was running Android 17 with the latest security patch, adding: "The exploit granted us unrestricted access to browse personal images stored on the device without requiring a single security check."
The outlet notes that different manufacturers have different permissions for lock screens, meaning it doesn't work on a Samsung Galaxy S25 Ultra running One UI 8.5.
Here, trying the Create with Meta AI button prompted users to enter a passcode or use a biometric scan.
On the reverse of this, an Oppo K13 running ColorOS 16 allowed access to the camera roll.
Is there a fix for the WhatsApp photo flaw?

Thankfully, this should be a relatively easy problem to solve, with mobile hacker explaining how you can stop the bug in its tracks. They highlight the prerequisite that WhatsApp already needs permission to access your photos and videos. This is normal for those who want to send media through the app.
Still, leaving a phone unattended at a desk or table while connected to the internet could be an issue.
To stop the flaw, open Settings on your Android device and head to Apps -> WhatsApp -> Permissions. Then select Photos and Videos before changing full access to Allow limited access.
iPhone users don't have to worry about the bug because CallKit restrictions display Apple's standard cellular interface instead of a custom WhatsApp screen and block any form of background replacement tool.
UNILADTech reached out to Meta, with confirmation that WhatsApp is already rolling out a fix for what was called a 'very limited scenario'.