A new lock screen bypass discovered in WhatsApp for Android is being flagged as a serious tool for stalkerware-style abuse. The trick doesn’t require malware, a jailbreak, or even a passcode guess — just an incoming video call and a few taps in a menu most people have never opened. Researcher Jose Rodriguez, who has spent years finding lock screen weaknesses on both Android and iOS, reported the flaw to Meta and Google, but as of publication no fix has shipped and the technique still works on at least some devices.
How a Video Call Turns Into a Gallery Browser
The attack path is almost absurdly simple. Someone with brief physical access to a locked Android phone places a WhatsApp video call to it. Because incoming calls can be answered from the lock screen without unlocking the device, the person holding the phone can accept the call with a swipe — no PIN, pattern, or fingerprint needed.
Once the call connects, the in-call interface offers an effects icon leading to tabs for filters, effects, and virtual backgrounds. Selecting the backgrounds tab and tapping “Create with Meta AI,” followed by “Edit photo,” opens a photo picker meant to let the caller choose an image for their background. Instead, on vulnerable devices, that picker exposes the phone’s entire local photo library — full access, no further authentication required.
Not Every Android Phone Is Affected the Same Way
Follow-up testing shared by security researcher Lukáš Štefanko showed the bypass isn’t universal. A Google Pixel 6 Pro and an Oppo K13 both allowed the full gallery to be browsed through the flaw, while a Samsung Galaxy S25 Ultra running One UI correctly bounced the request back to the lock screen and demanded authentication first. Apple devices are unaffected entirely, because iOS routes WhatsApp calls through Apple’s native CallKit interface, which blocks third-party apps from injecting their own in-call menus.
That inconsistency points to the root cause: this isn’t a flaw baked into core Android, but a byproduct of how individual manufacturers implement lock screen permissions and how WhatsApp’s in-call tools interact with them. Samsung’s stricter handling suggests the bypass is preventable at the OS or OEM level even before Meta ships a proper fix.
Why This Is More Than a Curiosity
The flaw’s real danger isn’t random opportunistic hacking — it’s targeted, low-effort surveillance. Anyone who knows a target’s WhatsApp number can call an unattended phone sitting on a nightstand, kitchen counter, or charging dock and silently flip through its saved photos. Security researchers have specifically called out its potential as a stalkerware technique, useful to abusive partners, jealous exes, or anyone else motivated to snoop without leaving obvious evidence. Because the exploit mimics ordinary call behavior and leaves no crash logs or suspicious notifications, victims have essentially no way to know their photo library was browsed.
With WhatsApp used by more than two billion people worldwide, even a narrow subset of vulnerable device models represents a large potential exposure. The episode also reinforces a broader pattern in mobile security: convenience features stacked on top of lock screens — call previews, quick replies, in-call creative tools — keep opening small side doors around the authentication users think is protecting their data.
What Users Can Do Right Now
Until Meta patches the underlying issue, there’s a practical workaround that doesn’t require disabling video calls altogether. Android users can limit the blast radius by restricting WhatsApp’s photo access:
- Open the phone’s Settings app and go to Apps (or Application Manager)
- Select WhatsApp, then tap Permissions
- Under Photos and videos, choose “Allow limited access” instead of full gallery access
- Manually select only the images WhatsApp actually needs, rather than granting it the entire library
With limited access enabled, the in-call photo picker can only reach the pre-approved subset of images rather than the full camera roll, effectively closing the loophole even if the underlying bug remains unpatched.
What to Watch For
Security teams and privacy-conscious users should treat this as a live issue rather than a theoretical one, since no patch timeline has been confirmed. People in relationships or households where device access could be misused — a common vector for stalkerware and intimate partner surveillance — are advised to apply the permission change immediately rather than waiting for an official update. Organizations that issue Android devices to staff may also want to push the restricted-permission setting through mobile device management policies until Meta and Google confirm a fix is available across affected models.
Leave a Reply
You must be logged in to post a comment.