WhatsApp Android Flaw Lets Attackers Bypass Lock Screen During Video Calls
Key Takeaways A critical vulnerability (CVE-2024-XXXX) in WhatsApp for Android allows attackers to bypass the lock screen during video calls, gaining unauthorized access to a device’s photo and...
Key Takeaways
- A critical vulnerability (CVE-2024-XXXX) in WhatsApp for Android allows attackers to bypass the lock screen during video calls, gaining unauthorized access to a device’s photo and video gallery.
- The flaw affects specific Android devices, including Google Pixel 6 Pro and Oppo K13, suggesting the issue lies in manufacturer-specific lock screen customizations rather than core Android.
- iPhones are not impacted due to Apple’s CallKit framework, which routes WhatsApp calls through the native iOS interface.
- A temporary workaround involves restricting WhatsApp’s photo and video access permissions to “Allow limited access” until an official patch is released.
Unpacking the WhatsApp Android Lock Screen Bypass Vulnerability
A significant security flaw has been identified in WhatsApp for Android, enabling an attacker to circumvent a device’s lock screen during an active video call. This vulnerability, tracked as CVE-2024-XXXX, could grant unauthorized access to a user’s photo and video gallery, raising serious privacy concerns for the messaging platform’s over two billion global users.
Table Of Content
Affected Devices and Root Cause Analysis
Tests conducted by security researchers revealed that devices such as the Google Pixel 6 Pro and Oppo K13 were susceptible to this bypass. Conversely, a Samsung Galaxy S25 Ultra running One UI successfully thwarted the exploit, redirecting the user to the lock screen and requiring proper authentication. This differential behavior strongly indicates that the vulnerability stems from how individual Android manufacturers implement and customize lock screen permissions, rather than an inherent flaw within the foundational Android operating system itself.
The mechanism behind the bypass appears to involve WhatsApp’s custom in-call menus and a background-replacement tool accessible during video calls. This tool, when activated, inadvertently provides a pathway around the lock screen’s authentication requirements, granting access to the device’s media library.
Why iPhones Remain Secure
Apple’s iOS platform remains unaffected by this particular vulnerability. This immunity is attributed to Apple’s CallKit framework, which mandates that all incoming WhatsApp calls are routed through the native iOS calling interface. This integration prevents WhatsApp from leveraging its custom in-call menus and, by extension, the problematic background-replacement feature that facilitates the bypass on Android devices.
What You Should Do
Until Meta releases an official patch for this vulnerability, users concerned about potential exposure should implement the following mitigation steps immediately:
- Restrict WhatsApp’s Photo and Video Permissions: Navigate to your phone’s application settings, locate WhatsApp, and modify its photo and video access permissions. Change this setting from “Full access” to “Allow limited access” or a similar restrictive option. This action prevents the app from accessing your entire media library, thereby closing the loophole.
- Stay Vigilant for Updates: Regularly check for and install any official updates from Meta for WhatsApp, or system updates from your device manufacturer (Google, Oppo, Samsung, etc.), as these will likely contain the permanent fix.
- Exercise Caution with Device Access: Be mindful of who has physical access to your device, particularly in environments where surveillance or misuse of personal data could be a concern.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.