WhatsApp Flaw Allows Gallery Access on Locked OPPO and Vivo Devices

While a locked smartphone screen usually provides a sense of security, a newly discovered flaw in WhatsApp demonstrates that this protection is not absolute. A software bug has been identified that, under specific conditions, allows users to bypass lock screen restrictions and gain unauthorized access to a device’s photo gallery without requiring a passcode or biometric authentication.
The Exploitation Mechanism
Security researcher Jose Rodriguez shared details of this vulnerability on the social media platform X, providing a practical demonstration of how the bypass works.
The issue occurs during WhatsApp video calls. When a user receives a video call on a locked Android device, the system allows them to answer without unlocking the phone—this is standard and expected behavior. However, the security lapse happens once the call is connected.
If a user taps the effects icon during the active call and selects the “Backgrounds” option, they are presented with a feature to create a background using Meta AI. By choosing the option to edit an existing photo, the application directly opens the device’s image gallery, entirely bypassing the lock screen security.
OPPO and vivo Devices Primarily Affected
This vulnerability does not impact all smartphones equally. According to current findings, the flaw specifically affects devices manufactured by OPPO and vivo. Conversely, Samsung smartphones have proven immune to this particular issue.
Security experts suggest that the root cause is not exclusively within the WhatsApp application itself. Instead, it likely stems from how the custom Android user interfaces developed by specific manufacturers handle lock screen permissions and features that are accessible without unlocking the device.
Physical Access is Required
It is important to note that this is not a traditional vulnerability that enables remote hacking. Rather, it is an improper handling of lock screen restrictions by hardware and software manufacturers. To exploit this flaw, an unauthorized individual must have physical access to the device and receive a video call at that exact moment.
The issue has already been officially reported to both Meta and Google, and it is expected that upcoming software updates will resolve this security gap shortly.
