What happened
This week a security researcher demonstrated a simple trick on Android phones. When a locked phone receives a WhatsApp video call, the call can be answered straight from the lock screen. From inside that call, WhatsApp’s photo-effects and background feature can be steered to open the phone’s photo gallery — and from there, the whole camera roll is visible. At no point does the phone ask for the PIN, pattern or fingerprint that normally protects it.
The important part for regular people is what it does not require: no password, no special equipment, and no hacking skill. It does, however, require someone to be physically holding your phone. This is a "someone picked up your phone" problem, not a "someone on the other side of the world" problem.
How worried should you be?
Keep it in proportion. Because the attacker needs your actual phone in their hands, this is not the kind of flaw that lets strangers online rifle through your pictures. The real risk is closer to home: a lost or stolen phone, or a moment when someone you would rather not trust is holding your device.
Meta and Google have been told about the problem, which is the normal path for getting it fixed. But at the time of writing there is no update released that closes it, so it is worth taking the one-minute step below yourself rather than waiting.
The two-minute fix
You do not have to uninstall anything. The cleanest fix is to stop giving WhatsApp access to your entire photo library, so that even if the bug is triggered there is little for it to show.
On Android: open Settings → Apps → WhatsApp → Permissions → Photos and videos, and change it from "Allow all" to "Allow limited access" (some phones call it "Selected photos") or "Ask every time". You can still pick and send individual photos in WhatsApp — it will just ask you each time instead of holding the keys to everything.
While you are in there, it is a good habit to scroll through your other apps and ask a simple question: does this app really need my whole camera roll? For most apps the answer is no. Limiting photo access is one of the highest-value privacy settings on a phone, and this bug is a good reminder to use it.
The bigger lesson: locked is not the same as sealed
It is tempting to think of a lock screen as a wall around everything on your phone. It is really more like a front door: it stops someone from casually walking in, but it was never meant to be the only thing standing between a stranger and your most private files. Apps you have granted broad access to can, through a bug like this one, become a side window.
That is why the safest place for the handful of photos, videos and documents you would never want a stranger to see is not the general camera roll at all. It is a separate, encrypted space — one that is protected by its own secret, and that other apps simply cannot reach even when they misbehave. A bug in one app should not be able to expose the things that matter most.
Where Sealby fits
Sealby does not fix WhatsApp, and it will not stop someone from picking up your phone. What it does is give your most sensitive photos, videos, notes and files a home of their own: encrypted on your device, opened only with your own PIN or passphrase, and kept out of the shared camera roll that ordinary apps can see. So when the next "locked phone was not so locked" story appears — and there is always a next one — the things you care about most are not sitting where a single app’s mistake can reach them.