Technology

Privacy Concerns Growing Over WhatsApp Android Vulnerability

WhatsApp Android Vulnerability

A newly reported WhatsApp Android vulnerability can expose photos on some locked Android phones during an incoming video call. The issue requires physical access and appears to depend on the phone maker’s handling of lock-screen permissions. More than 3.3 billion people use the same green app worldwide, assuming they have secured it properly. Latest research suggests otherwise.

KEY POINTS
  • A lock screen bypass exposed galleries on some Pixel and Oppo handsets without a PIN.
  • Google’s Project Zero disclosed a separate zero-click group media flaw, now patched.
  • Group chats still lack cryptographic membership control, a gap first flagged in 2017.
  • The big 2026 WhatsApp malware waves hit Windows, not Android phones.
  • Britain’s NCSC has issued fresh advice for people at higher risk.

Lock Screen Photo Bypass During Video Calls

This one needs no coding skill. Independent researcher Jose Rodriguez published it on X on 1 September 2026, calling it “hidden in plain sight”. A locked Android phone receives a video call. Whoever holds it swipes to answer, which is normal. They then tap the effects icon, switch to backgrounds, choose Select “Create with Meta AI”, and then choose the edit photo option. The media picker opens, and the full gallery appears. No PIN. No fingerprint. Testing by NotebookCheck found the path worked on a Pixel 6 Pro running Android 17 and an Oppo K13 on ColorOS 16.

A Samsung Galaxy S25 Ultra on One UI 8.5 blocked it and demanded authentication. Risk depends on how each manufacturer handles lock screen boundaries. Heise reported that the bypass only reveals photos. It does not unlock the device, and images cannot be forwarded or edited. A snooper could still photograph the screen. iPhones are immune. Apple’s CallKit framework forces WhatsApp to use the native iOS call screen, so the custom effects menu never appears. Status: Meta began rolling out a fix on 3 September 2026, calling it a rare scenario needing physical access.

Also Read: Apple Watch Ultra 4: Price, Features, Battery Life and What’s New in 2026

Zero-Click Media Delivery in Group Chats

Google Project Zero researcher Brendon Tiszka reported a very different problem to Meta on 1 September 2025. It went public on 26 January 2026 after the standard 90-day deadline lapsed. An attacker creates a group, adds the target plus one of their real contacts, then often promotes that contact to admin so it looks genuine. A crafted media file follows.

With auto-download on, the phone fetches and processes it without a tap. Wizard Cyber states that WhatsApp acts as a trusted transport layer. This is not remote code execution by itself. The danger is an attacker-chosen file landing in storage, where Android’s media stack or gallery apps may parse it. Affected builds were 2.25.22.80 and 2.25.23.81. A partial server-side mitigation arrived in late 2025. Project Zero pushed back, and Meta shipped a comprehensive fix by late January 2026.

Group Chats Without Cryptographic Membership Control

Researchers at King’s College London, Martin R. Albrecht and Benjamin Dowling, with Royal Holloway PhD student Daniel Jones, reverse-engineered the app. Their EuroCrypt 2025 paper was a world first. The good news is that they proved the end-to-end encryption holds up, so Meta cannot read your messages. The problem sits with groups. Membership changes are handled by the server, not by cryptography, and are not limited to existing members.

Anyone controlling those servers could slip a silent observer into a chat. Albrecht warned that responsibility for securing group chats falls on users, not the platform, which is unworkable for groups with hundreds of members. Telegram and Matrix share the weakness. Signal does not.

Also Read: From Me, Natalie to Dead Man’s Wire: Al Pacino’s Net Worth

List of WhatsApp Android Flaws

Vulnerability Year Risk Fixed?
Lock screen photo bypass 2026 Gallery viewed on locked phone Fix rolling out
Zero-click group media 2025–26 Hostile file placed on device Yes, Jan 2026
No membership integrity 2017–25 Silent additions to group chats No, design level
CVE-2022-36934 2022 Code execution in a live video call Yes
CVE-2019-11932 2019 Malicious GIF triggered remote code execution Yes, v2.19.244

That 2019 GIF bug sat in an open-source library, not WhatsApp’s own code, and fired when the gallery was opened.

The Malware Campaigns That Are Not Android Bugs

Microsoft Defender Experts tracked a campaign from late February 2026 spreading Visual Basic Script files through WhatsApp messages. It renamed Windows tools, pulled payloads from cloud hosts such as AWS, weakened User Account Control, then installed unsigned MSI packages. Kaspersky’s GReAT team documented a similar wave in June 2026, with the UK among affected countries and 80% of victims in Malaysia.

Hijacked accounts sent files named like invoices and bank statements. Both target WhatsApp Desktop and Web on Windows. Neither exploits a hole in the Android app. WhatsApp is simply the postbox.

What UK Users Should Do Now

The NCSC warned in March 2026 about Russia-based actors targeting messaging apps, adding a protection infographic in July. Update WhatsApp through the Play Store. Open Settings, Apps, WhatsApp, and Permissions, then set photos and videos to limited access. Turn off media auto-download in Storage and Data. Switch on two-step verification and passkeys.  Check linked devices, review group members, and remove anyone you cannot verify. Convenience keeps winning out over caution in app design. Your lock screen is only as strong as the shortcuts on top of it.

FAQs

Is WhatsApp safe on Android in 2026?

Ans: Yes, as message encryption remains intact. Recent issues involved photo access and file delivery, not broken encryption. Updating the app closes most of the gap.

What is the WhatsApp Android vulnerability?

Ans: It is a lock screen bypass found on 1 September 2026. Answering a video call on a locked phone opens a route into the gallery via the Meta AI background tool.

Has WhatsApp fixed the photo bug?

Ans: Meta confirmed a fix began rolling out on 3 September 2026. Update through the Play Store, as staged rollouts reach handsets at different times.

Can someone read my WhatsApp remotely?

Ans: No, these flaws are patched. The photo bug needs physical access, and the group media bug was resolved in January 2026.

How do I stop WhatsApp seeing all my photos?

Ans: Open Settings, then Apps, then WhatsApp, then Permissions, then Photos and Videos. Choose limited access and select only the images the app may access.

Are iPhones affected by this flaw?

Ans: No. Apple’s CallKit framework forces incoming calls onto the native iOS screen, so the effects menu enabling the bypass never loads.

Sources & References:

  • KCLResearchers at King’s College London proved that the end-to-end encryption holds up, so Meta cannot read your messages.
  • MicrosoftTracked a campaign from late February 2026 spreading Visual Basic Script files through WhatsApp messages.
  • HeiseThe bypass only reveals photos.
  • Wizard CyberWhatsApp serves as a trusted transport layer.
Lyra Vance

Lyra Vance

Lyra Vance is a writer and editor at The Daily Dispatch, covering Business, Economy, Entrepreneur, News, and Technology.

With a freelance and mixed-background career spanning several years across digital publishing, she brings a practical, research-driven approach to reporting on the stories behind the headlines — from shifts in UK economic policy to the technology decisions shaping how businesses and consumers operate day to day.

Before joining The Daily Dispatch, Lyra worked as a freelance writer across business and technology beats, building a broad understanding of how newsrooms cover fast-moving stories and translate complex developments into clear, accessible reporting.

At The Daily Dispatch, Lyra edits and reports on breaking business news and technology trends, with an emphasis on accuracy, context, and explaining real-world impact over hype or speculation.

Read more

Leave a Reply

Your email address will not be published. Required fields are marked *