A newly disclosed attack chain can potentially let someone with physical access to a locked Android phone browse its photo gallery through an incoming WhatsApp video call. The path is essentially: WhatsApp call → Effects → Backgrounds → Meta AI → Edit Photo → Gallery No PIN, pattern, or biometric authentication is required once the vulnerable path is available. Testing found the behavior on some Pixel and Oppo devices, while Samsung’s One UI blocked the same path with authentication.

      • sbird@sopuli.xyz
        link
        fedilink
        English
        arrow-up
        2
        ·
        edit-2
        2 days ago

        Neither, the former is only on iOS / various other Apple bits, the latter is awful in terms of privacy (arguably more so than Whatsapp)

        I mainly use Matrix (Element on desktop, FluffyChat on Android, Fractal on mobile Linux) and email (Thunderbird), but I also have Halloy (IRC) installed to. As for any proprietary messaging services I use, it’s mainly WeChat for messaging Chinese friends.

        edit: I also have Signal, but pretty much no one in my circle uses it, as everybody who was bothered to switch to Signal went all the way and joined Matrix in my experience.

  • limerod@reddthat.com
    link
    fedilink
    English
    arrow-up
    2
    ·
    3 days ago

    Good thing I never granted the read media permission. Whatsapp can use the default photo picker for pictures and video and repeatedly asks for storage permission claiming it becomes limited without it.

    I need to manually invoke the media picker whenever I want to send a picture. This lock screen bypass does not work in my case since I never granted the storage or read media permission to whatsapp.