A security researcher has discovered a lock screen bypass vulnerability in WhatsApp for Android that allows unauthorized access to a device’s photo gallery via incoming video calls. Independent security researcher José Rodríguez revealed the bug, which requires physical access to the target smartphone to execute.
Lock Screen Bypass Exposes Device Galleries Through Video Calls
According to Rodríguez, the exploit sequence initiates when an attacker utilizes an incoming video call on a locked device and navigates to available call effects. By interacting with the “Create with Meta AI” and “Edit photo” options, the interface bypasses the lock screen security controls and opens the device’s photo gallery.
Hardware Discrepancies Across Android Manufacturers
The vulnerability impacts specific Android hardware configurations differently, depending on manufacturer-specific software implementations. Rodríguez reported that the exploit successfully affects devices such as the Oppo K13 and the Google Pixel 6.
Conversely, testing on the Samsung Galaxy S25 Ultra showed that the device is not vulnerable to this specific attack chain. This variance indicates that different original equipment manufacturers utilize distinct implementations of lock screen security overlays or handle WhatsApp’s deep system integrations in unique ways.
Missing Patches and Manual Risk Mitigation
Meta and WhatsApp have not yet released an official statement, security advisory, or software patch addressing this specific lock screen bypass. Until an official update rolls out, users can employ manual workarounds to mitigate the risk of unauthorized physical access.
Rodríguez advises users to restrict WhatsApp’s application permissions directly within the Android system settings. Alternatively, revoking the app’s camera access entirely disrupts the command chain required to launch the video call effects and Meta AI features from the lock screen.
Limitations of Existing Account-Level Protections
This discovery emerges alongside recent platform updates focused on account-level protections, such as enhanced two-step verification using alphanumeric passwords and multi-passkey support across accounts. However, those cryptographic account features target credential theft and remote phishing campaigns, leaving physical device interaction vectors like the lock screen video call flaw unmitigated without manual permission adjustments.
