WeChat promises to stop accessing users’ photo albums amid public outcry

A tech blogger claimed that popular Chinese apps snoop around users' photo libraries, provoking heightened public concerns over privacy.

A hand holding a smartphone.

A survey launched by Sina Tech shows 94% of the some 30,000 responding users said they are not comfortable with apps reading their photo libraries just to allow them to share images faster in chats.

Photo: S3studio via Getty Images

A Chinese tech blogger dropped a bombshell last Friday, claiming on Chinese media that he found that several popular Chinese apps, including the Tencent-owned chat apps WeChat and QQ, as well as the Alibaba-owned ecommerce app Taobao, frequently access iPhone users' photo albums in the background even when those apps are not in use.

The original Weibo post from the tech blogger, using the handle of @Hackl0us, provoked intense debates about user privacy on the Chinese internet and consequently prompted WeChat to announce that it would stop fetching users' photo album data in the background.

@Hackl0us said he tracked the apps' activities for seven days using a new iOS 15 feature called Record App Activity, along with a third-party app called App Privacy Insights. Screenshots of activity logs provided by @Hackl0us show that the three Chinese apps read his photos multiple times throughout the day with each read lasting up to 60 seconds.

"This is disgusting," @Hackl0us wrote. "Photos are a user's private [possession]. They have no idea when the apps fetch their private data. Judging from the log, the apps read the photo library even while the user is asleep."

Chinese web users reacted strongly to @Hackl0us' findings. His original Weibo post trended on the platform's hot search chart last Friday. By the time of this writing, his post has been shared over 50,000 times, and nearly 220,000 people have liked it. A related hashtag has received 200 million reads. In a survey launched by Sina Tech on Weibo, 94% of some 30,000 respondents said they are not comfortable with apps reading their photo libraries.

WeChat, one of the most frequently used apps in China with over 1.2 billion users, immediately responded through Chinese media. The company explained that an Apple protocol, which web users identified as the PHPhotoLibraryChangeObserver, notifies app developers of changes that occur in their user' photos libraries. The protocol allows an app to track changes within and outside the app. When an app receives those change messages, the iOS 15 system records the activity as if it were photos being read on a user's phone.

WeChat explained this protocol allows users to share photos faster in chats, causing a preview of the last photo in a user's album to pop up. WeChat stressed in its statement that the processing is on-device, and that app was able to do this because users gave their consent by authorizing WeChat to access their albums.

"We do not collect, save, or upload any images from a user's album without the user's authorization," a Tencent spokesperson wrote in a statement shared with Protocol.

WeChat promised that it would withdraw the background fetching protocol in its next update, and it is finding an alternative to "optimize the quick picture sending function.

But WeChat's statement didn't fully address privacy concerns. In a Zhihu article where @Hackl0us documented his complaint, he wrote that WeChat's technical teams had reached out to him and explained why WeChat decided to enable the image posting feature through background data fetching. But @Hackl0us believes WeChat is breaking a butterfly on a wheel. He argued that WeChat could achieve the same feature in alternative ways without systematically reading photo libraries in the background. Not only does invoking this protocol intrude on user privacy, @Hackl0us said, it consumes unnecessary memory and battery at the expense of user experience.

"I really don't understand why WeChat needs to use Apple's PHPhotoLibraryChangeObserver protocol to implement such a simple feature," he wrote. "It's probably fine for one app to do this, but if many Chinese apps act like this, and they do, it will have a big impact on our phone's battery life."

Legitimate privacy concerns

Digital privacy experts told Protocol that app developers seeing a list of photo changes by itself offers very limited utility, but if the apps can access the photos themselves, they could exploit Apple's PHPhotoLibraryChangeObserver protocol to analyze user behavior or sentiment, which is of great commercial value. Apps could also run facial recognition algorithms to facilitate social mapping.

"WeChat is closed-source software, so it is impossible to know how the protocol is implemented, what it does, and whether it is commercialized by generating a library of fingerprints from user albums until we see the source code," @Hackl0us wrote in his Zhihu article.

The controversy over privacy occurred less than one month before China's privacy law, the Personal Information Protection Law (PIPL), becomes effective. This law will shield Chinese internet users from excessive data collection and misuse of personal data by tech companies. One big theme running throughout the law is ensuring the consumer's right to consent and the right to know how their information is being used. Data handlers are required to collect data only when necessary to provide certain services, and must secure user consent for the collection.

Without knowing more details of app developers' processes on the device and regulations, it's hard to know whether the action of frequently reading photo albums would violate the forthcoming Personal Information Protection Law, according to Graham Webster, a research scholar at the Stanford University Cyber Policy Center and the editor in chief of the center's DigiChina Project.

"One real question is whether on-device processes limited to functional needs for the app even constitute 'personal information handling' under the law," Webster told Protocol. "Meanwhile, it seems it would be impossible to know ahead of time whether a given photo qualifies as 'sensitive personal information.'"

Under PIPL, data handlers are required to obtain "separate consent" from users while dealing with "sensitive personal information" and inform them of the necessity of collecting such data as well as the impact on their rights.

The law is new. Companies and consumers should expect more detailed regulations to clarify questions like this. "Depending on the details, [the background fetching of albums data] could well be a legitimate privacy concern, even if it isn't one that's covered in the new law," Webster said.


Gavin Newsom shows crypto some California love

“A more flexible approach is needed,” Gov. Newsom said in rejecting a bill that would require crypto companies to get a state license.

Strong bipartisan support wasn’t enough to convince Newsom that requiring crypto companies to register with the state’s Department of Financial Protection and Innovation is the smart path for California.

Photo: Jerod Harris/Getty Images for Vox Media

The Digital Financial Assets Law seemed like a legislative slam dunk in California for critics of the crypto industry.

But strong bipartisan support — it passed 71-0 in the state assembly and 31-6 in the Senate — wasn’t enough to convince Gov. Gavin Newsom that requiring crypto companies to register with the state’s Department of Financial Protection and Innovation is the smart path for California.

Keep Reading Show less
Benjamin Pimentel

Benjamin Pimentel ( @benpimentel) covers crypto and fintech from San Francisco. He has reported on many of the biggest tech stories over the past 20 years for the San Francisco Chronicle, Dow Jones MarketWatch and Business Insider, from the dot-com crash, the rise of cloud computing, social networking and AI to the impact of the Great Recession and the COVID crisis on Silicon Valley and beyond. He can be reached at or via Google Voice at (925) 307-9342.

Sponsored Content

Great products are built on strong patents

Experts say robust intellectual property protection is essential to ensure the long-term R&D required to innovate and maintain America's technology leadership.

Every great tech product that you rely on each day, from the smartphone in your pocket to your music streaming service and navigational system in the car, shares one important thing: part of its innovative design is protected by intellectual property (IP) laws.

From 5G to artificial intelligence, IP protection offers a powerful incentive for researchers to create ground-breaking products, and governmental leaders say its protection is an essential part of maintaining US technology leadership. To quote Secretary of Commerce Gina Raimondo: "intellectual property protection is vital for American innovation and entrepreneurship.”

Keep Reading Show less
James Daly
James Daly has a deep knowledge of creating brand voice identity, including understanding various audiences and targeting messaging accordingly. He enjoys commissioning, editing, writing, and business development, particularly in launching new ventures and building passionate audiences. Daly has led teams large and small to multiple awards and quantifiable success through a strategy built on teamwork, passion, fact-checking, intelligence, analytics, and audience growth while meeting budget goals and production deadlines in fast-paced environments. Daly is the Editorial Director of 2030 Media and a contributor at Wired.

Slack’s rallying cry at Dreamforce: No more meetings

It’s not all cartoon bears and therapy pigs — work conferences are a good place to talk about the future of work.

“We want people to be able to work in whatever way works for them with flexible schedules, in meetings and out of meetings,” Slack chief product officer Tamar Yehoshua told Protocol at Dreamforce 2022.

Photo: Marlena Sloss/Bloomberg via Getty Images

Dreamforce is primarily Salesforce’s show. But Slack wasn’t to be left out, especially as the primary connector between Salesforce and the mainstream working world.

The average knowledge worker spends more time using a communication tool like Slack than a CRM like Salesforce, positioning it as the best Salesforce product to concern itself with the future of work. In between meeting a therapy pig and meditating by the Dreamforce waterfall, Protocol sat down with several Slack execs and conference-goers to chat about the shifting future.

Keep Reading Show less
Lizzy Lawrence

Lizzy Lawrence ( @LizzyLaw_) is a reporter at Protocol, covering tools and productivity in the workplace. She's a recent graduate of the University of Michigan, where she studied sociology and international studies. She served as editor in chief of The Michigan Daily, her school's independent newspaper. She's based in D.C., and can be reached at

LA is a growing tech hub. But not everyone may fit.

LA has a housing crisis similar to Silicon Valley’s. And single-family-zoning laws are mostly to blame.

As the number of tech companies in the region grows, so does the number of tech workers, whose high salaries put them at an advantage in both LA's renting and buying markets.

Photo: Nat Rubio-Licht/Protocol

LA’s tech scene is on the rise. The number of unicorn companies in Los Angeles is growing, and the city has become the third-largest startup ecosystem nationally behind the Bay Area and New York with more than 4,000 VC-backed startups in industries ranging from aerospace to creators. As the number of tech companies in the region grows, so does the number of tech workers. The city is quickly becoming more and more like Silicon Valley — a new startup and a dozen tech workers on every corner and companies like Google, Netflix, and Twitter setting up offices there.

But with growth comes growing pains. Los Angeles, especially the burgeoning Silicon Beach area — which includes Santa Monica, Venice, and Marina del Rey — shares something in common with its namesake Silicon Valley: a severe lack of housing.

Keep Reading Show less
Nat Rubio-Licht

Nat Rubio-Licht is a Los Angeles-based news writer at Protocol. They graduated from Syracuse University with a degree in newspaper and online journalism in May 2020. Prior to joining the team, they worked at the Los Angeles Business Journal as a technology and aerospace reporter.


SFPD can now surveil a private camera network funded by Ripple chair

The San Francisco Board of Supervisors approved a policy that the ACLU and EFF argue will further criminalize marginalized groups.

SFPD will be able to temporarily tap into private surveillance networks in certain circumstances.

Photo: Justin Sullivan/Getty Images

Ripple chairman and co-founder Chris Larsen has been funding a network of security cameras throughout San Francisco for a decade. Now, the city has given its police department the green light to monitor the feeds from those cameras — and any other private surveillance devices in the city — in real time, whether or not a crime has been committed.

This week, San Francisco’s Board of Supervisors approved a controversial plan to allow SFPD to temporarily tap into private surveillance networks during life-threatening emergencies, large events, and in the course of criminal investigations, including investigations of misdemeanors. The decision came despite fervent opposition from groups, including the ACLU of Northern California and the Electronic Frontier Foundation, which say the police department’s new authority will be misused against protesters and marginalized groups in a city that has been a bastion for both.

Keep Reading Show less
Issie Lapowsky

Issie Lapowsky ( @issielapowsky) is Protocol's chief correspondent, covering the intersection of technology, politics, and national affairs. She also oversees Protocol's fellowship program. Previously, she was a senior writer at Wired, where she covered the 2016 election and the Facebook beat in its aftermath. Prior to that, Issie worked as a staff writer for Inc. magazine, writing about small business and entrepreneurship. She has also worked as an on-air contributor for CBS News and taught a graduate-level course at New York University's Center for Publishing on how tech giants have affected publishing.

Latest Stories