Skip to finding
§
High
Mobile — Android
Confirmed

A permissionless Android app can reconstruct private WhatsApp media activity across scoped storage.

Public source code and an APK reproduce the cross-application FileObserver path without requesting Android permissions.

Affects

Android applications using FileObserver, demonstrated against WhatsApp media stored through Android shared storage.

What it enables

Cross-application observation of private media activity, filenames and timing

The victim installs or runs an ordinary attacker-controlled Android application requiring no permissions.→↓The application registers FileObserver watches on WhatsApp shared-media directories that scoped storage otherwise prevents it from listing.→↓Android delivers filenames, event types and timing for files opened, closed, moved or deleted by WhatsApp.→↓The attacker reconstructs whether private media was sent, received or deleted and identifies associated filenames and media types.
Why this matters

The change is reachability: metadata about another application's private activity is available to ordinary permissionless code.

Detail, proof-of-concept code and 5 sources
Required access

Execution as an ordinary Android application requesting no permissions

Proof of concept

Public exploit code →

The attacker watches WhatsApp shared-media directories that scoped storage otherwise prevents it from listing, then receives filenames, event types and timing when WhatsApp opens, closes, moves or deletes files.

Those events are enough to infer whether private media was sent, received or deleted and to identify its filename and media type.

Evidence
The public research artifact includes Android source code and an APK demonstrating permissionless WhatsApp media-event monitoring.The paper and independent reporting describe the FileObserver/FUSE boundary crossing and recovered metadata.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 26, 2026