A permissionless Android app can reconstruct private WhatsApp media activity across scoped storage.
Public source code and an APK reproduce the cross-application FileObserver path without requesting Android permissions.
Affects
Android applications using FileObserver, demonstrated against WhatsApp media stored through Android shared storage.
What it enables
Cross-application observation of private media activity, filenames and timing
The victim installs or runs an ordinary attacker-controlled Android application requiring no permissions.→↓The application registers FileObserver watches on WhatsApp shared-media directories that scoped storage otherwise prevents it from listing.→↓Android delivers filenames, event types and timing for files opened, closed, moved or deleted by WhatsApp.→↓The attacker reconstructs whether private media was sent, received or deleted and identifies associated filenames and media types.
Why this matters
The change is reachability: metadata about another application's private activity is available to ordinary permissionless code.
Detail, proof-of-concept code and 5 sources
Required access
Execution as an ordinary Android application requesting no permissions
The attacker watches WhatsApp shared-media directories that scoped storage otherwise prevents it from listing, then receives filenames, event types and timing when WhatsApp opens, closes, moves or deletes files.
Those events are enough to infer whether private media was sent, received or deleted and to identify its filename and media type.
Evidence
The public research artifact includes Android source code and an APK demonstrating permissionless WhatsApp media-event monitoring.The paper and independent reporting describe the FileObserver/FUSE boundary crossing and recovered metadata.
The same brief, every morning. One email a day, nothing else.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.