Android WhatsApp Bug Lets Private Photos Load Without Unlock

A recently discovered flaw in WhatsApp for Android can expose private photos on a locked device without the phone being unlocked. This behavior is unintended and poses a clear privacy risk for users who believe their locked phone prevents visual access to sensitive images.

The issue was first highlighted on social media by @VBarraquito and later verified by other researchers, including “Mobile Hacker” and NotebookCheck. In short, the flaw takes advantage of the way WhatsApp handles incoming calls and the in-call interface on some Android phones. When a WhatsApp call arrives, the call screen can be answered without unlocking the device, similar to a regular phone call. From that in-call screen, a user (or an attacker with temporary access) can open camera filters and effects, including the AI-powered photo editing and preview tools that WhatsApp provides.

Instead of requiring the phone to be unlocked before showing images, the app displays a photo preview and editing options while the device remains on the lock screen. That preview can reveal private photos stored on the device, effectively allowing visual access to images without entering a PIN, password, or biometric authentication.

This bypass is not consistent across all Android hardware. NotebookCheck’s testing found that at least one Samsung Galaxy device enforces the lockscreen before allowing the filter and preview interface to open, preventing the bypass. By contrast, Pixel and Oppo models tested were susceptible and allowed full access to the photo preview without unlocking. The exploit does not appear on iPhone, because WhatsApp on iOS uses the native calling interface which enforces stricter lockscreen behavior.

The plastic piece visible in the demonstration is unrelated to the exploit and appears used only to obscure a contact name.

There is some limited good news: the vulnerability does not appear to grant broader access to the device. Other apps, files, or system settings remain protected by the lockscreen, and the attacker cannot directly export or copy the images from the phone using the in-call preview. The primary risk is that a person with brief physical access to the device—or someone able to prompt and answer a WhatsApp call—can view private photos on screen. That person could, however, use a secondary camera or another phone to take pictures of those visible images, which still represents a meaningful privacy breach.

WhatsApp can address the issue with a software update that ensures the app enforces lockscreen protections before allowing any photo preview or editing UI to appear during calls. The vulnerability has been reported to both WhatsApp and Google, but no official patch has been released at the time of writing.

Until an official fix is available, users can reduce exposure by limiting WhatsApp’s access to photos and videos through Android’s permission settings. Setting WhatsApp’s media access to “limited” in Android permissions prevents the app from displaying the full photo library in that preview interface and is an effective temporary mitigation against this specific bypass.

More on WhatsApp:

  • WhatsApp two-step verification codes are replacing six-digit PINs with full passwords, improving account security.
  • New group chat features, including an “@all” tag, have recently been added to improve group communication.
  • Android Auto has begun rolling out upgraded WhatsApp support, enhancing in-car messaging and calling functionality.

Follow Ben: Twitter/X, Threads, Bluesky, and Instagram