Overview
- Security researcher Jose Rodriguez posted a public demonstration of the flaw that shows an incoming WhatsApp video call can be used to reach the app’s filters and image‑edit tools and then open the phone’s photo gallery without unlocking the device.
- The exploit works from WhatsApp’s in-call user interface by selecting effects or the Create with Meta AI path and then choosing Edit photo to reach stored images inside the app.
- Testing by outlets found the issue varies by device and manufacturer so some Android phones such as certain Google and Oppo models are affected while some Samsung One UI and iPhone models are not.
- Meta has confirmed the vulnerability and begun rolling out an app update to fix it, and the company recommends that users restrict WhatsApp’s photo permissions until the patch arrives.
- Users with sensitive images should consider turning off WhatsApp photo access or using an incoming-call lock app to require a PIN for calls because the flaw needs physical access to the locked phone but still lets an attacker view images or photograph the screen.