WeChat promises to stop accessing users’ photo albums amid public outcry

A tech blogger claimed that popular Chinese apps snoop around users' photo libraries, provoking heightened public concerns over privacy.

A hand holding a smartphone.

A survey launched by Sina Tech shows 94% of the some 30,000 responding users said they are not comfortable with apps reading their photo libraries just to allow them to share images faster in chats.

Photo: S3studio via Getty Images

A Chinese tech blogger dropped a bombshell last Friday, claiming on Chinese media that he found that several popular Chinese apps, including the Tencent-owned chat apps WeChat and QQ, as well as the Alibaba-owned ecommerce app Taobao, frequently access iPhone users' photo albums in the background even when those apps are not in use.

The original Weibo post from the tech blogger, using the handle of @Hackl0us, provoked intense debates about user privacy on the Chinese internet and consequently prompted WeChat to announce that it would stop fetching users' photo album data in the background.

@Hackl0us said he tracked the apps' activities for seven days using a new iOS 15 feature called Record App Activity, along with a third-party app called App Privacy Insights. Screenshots of activity logs provided by @Hackl0us show that the three Chinese apps read his photos multiple times throughout the day with each read lasting up to 60 seconds.

"This is disgusting," @Hackl0us wrote. "Photos are a user's private [possession]. They have no idea when the apps fetch their private data. Judging from the log, the apps read the photo library even while the user is asleep."

Chinese web users reacted strongly to @Hackl0us' findings. His original Weibo post trended on the platform's hot search chart last Friday. By the time of this writing, his post has been shared over 50,000 times, and nearly 220,000 people have liked it. A related hashtag has received 200 million reads. In a survey launched by Sina Tech on Weibo, 94% of some 30,000 respondents said they are not comfortable with apps reading their photo libraries.

WeChat, one of the most frequently used apps in China with over 1.2 billion users, immediately responded through Chinese media. The company explained that an Apple protocol, which web users identified as the PHPhotoLibraryChangeObserver, notifies app developers of changes that occur in their user' photos libraries. The protocol allows an app to track changes within and outside the app. When an app receives those change messages, the iOS 15 system records the activity as if it were photos being read on a user's phone.

WeChat explained this protocol allows users to share photos faster in chats, causing a preview of the last photo in a user's album to pop up. WeChat stressed in its statement that the processing is on-device, and that app was able to do this because users gave their consent by authorizing WeChat to access their albums.

"We do not collect, save, or upload any images from a user's album without the user's authorization," a Tencent spokesperson wrote in a statement shared with Protocol.

WeChat promised that it would withdraw the background fetching protocol in its next update, and it is finding an alternative to "optimize the quick picture sending function.

But WeChat's statement didn't fully address privacy concerns. In a Zhihu article where @Hackl0us documented his complaint, he wrote that WeChat's technical teams had reached out to him and explained why WeChat decided to enable the image posting feature through background data fetching. But @Hackl0us believes WeChat is breaking a butterfly on a wheel. He argued that WeChat could achieve the same feature in alternative ways without systematically reading photo libraries in the background. Not only does invoking this protocol intrude on user privacy, @Hackl0us said, it consumes unnecessary memory and battery at the expense of user experience.

"I really don't understand why WeChat needs to use Apple's PHPhotoLibraryChangeObserver protocol to implement such a simple feature," he wrote. "It's probably fine for one app to do this, but if many Chinese apps act like this, and they do, it will have a big impact on our phone's battery life."

Legitimate privacy concerns

Digital privacy experts told Protocol that app developers seeing a list of photo changes by itself offers very limited utility, but if the apps can access the photos themselves, they could exploit Apple's PHPhotoLibraryChangeObserver protocol to analyze user behavior or sentiment, which is of great commercial value. Apps could also run facial recognition algorithms to facilitate social mapping.

"WeChat is closed-source software, so it is impossible to know how the protocol is implemented, what it does, and whether it is commercialized by generating a library of fingerprints from user albums until we see the source code," @Hackl0us wrote in his Zhihu article.

The controversy over privacy occurred less than one month before China's privacy law, the Personal Information Protection Law (PIPL), becomes effective. This law will shield Chinese internet users from excessive data collection and misuse of personal data by tech companies. One big theme running throughout the law is ensuring the consumer's right to consent and the right to know how their information is being used. Data handlers are required to collect data only when necessary to provide certain services, and must secure user consent for the collection.

Without knowing more details of app developers' processes on the device and regulations, it's hard to know whether the action of frequently reading photo albums would violate the forthcoming Personal Information Protection Law, according to Graham Webster, a research scholar at the Stanford University Cyber Policy Center and the editor in chief of the center's DigiChina Project.

"One real question is whether on-device processes limited to functional needs for the app even constitute 'personal information handling' under the law," Webster told Protocol. "Meanwhile, it seems it would be impossible to know ahead of time whether a given photo qualifies as 'sensitive personal information.'"

Under PIPL, data handlers are required to obtain "separate consent" from users while dealing with "sensitive personal information" and inform them of the necessity of collecting such data as well as the impact on their rights.

The law is new. Companies and consumers should expect more detailed regulations to clarify questions like this. "Depending on the details, [the background fetching of albums data] could well be a legitimate privacy concern, even if it isn't one that's covered in the new law," Webster said.


Google is wooing a coalition of civil rights allies. It’s working.

The tech giant is adept at winning friends even when it’s not trying to immediately influence people.

A map display of Washington lines the floor next to the elevators at the Google office in Washington, D.C.

Photo: Andrew Harrer/Bloomberg via Getty Images

As Google has faced intensifying pressure from policymakers in recent years, it’s founded trade associations, hired a roster of former top government officials and sometimes spent more than $20 million annually on federal lobbying.

But the company has also become famous in Washington for nurturing less clearly mercenary ties. It has long funded the work of laissez-faire economists who now defend it against antitrust charges, for instance. It’s making inroads with traditional business associations that once pummeled it on policy, and also supports think tanks and advocacy groups.

Keep Reading Show less
Ben Brody

Ben Brody (@ BenBrodyDC) is a senior reporter at Protocol focusing on how Congress, courts and agencies affect the online world we live in. He formerly covered tech policy and lobbying (including antitrust, Section 230 and privacy) at Bloomberg News, where he previously reported on the influence industry, government ethics and the 2016 presidential election. Before that, Ben covered business news at CNNMoney and AdAge, and all manner of stories in and around New York. He still loves appearing on the New York news radio he grew up with.

Sustainability. It can be a charged word in the context of blockchain and crypto – whether from outsiders with a limited view of the technology or from insiders using it for competitive advantage. But as a CEO in the industry, I don’t think either of those approaches helps us move forward. We should all be able to agree that using less energy to get a task done is a good thing and that there is room for improvement in the amount of energy that is consumed to power different blockchain technologies.

So, what if we put the enormous industry talent and minds that have created and developed blockchain to the task of building in a more energy-efficient manner? Can we not just solve the issues but also set the standard for other industries to develop technology in a future-proof way?

Keep Reading Show less
Denelle Dixon, CEO of SDF

Denelle Dixon is CEO and Executive Director of the Stellar Development Foundation, a non-profit using blockchain to unlock economic potential by making money more fluid, markets more open, and people more empowered. Previously, Dixon served as COO of Mozilla. Leading the business, revenue and policy teams, she fought for Net Neutrality and consumer privacy protections and was responsible for commercial partnerships. Denelle also served as general counsel and legal advisor in private equity and technology.


Everything you need to know about tech layoffs and hiring slowdowns

Will tech companies and startups continue to have layoffs?

It’s not just early-stage startups that are feeling the burn.

Photo: Kirsty O'Connor/PA Images via Getty Images

What goes up must come down.

High-flying startups with record valuations, huge hiring goals and ambitious expansion plans are now announcing hiring slowdowns, freezes and in some cases widespread layoffs. It’s the dot-com bust all over again — this time, without the cute sock puppet and in the midst of a global pandemic we just can’t seem to shake.

Keep Reading Show less
Nat Rubio-Licht

Nat Rubio-Licht is a Los Angeles-based news writer at Protocol. They graduated from Syracuse University with a degree in newspaper and online journalism in May 2020. Prior to joining the team, they worked at the Los Angeles Business Journal as a technology and aerospace reporter.


Sink into ‘Love, Death & Robots’ and more weekend recs

Don’t know what to do this weekend? We’ve got you covered.

Our favorite picks for your weekend pleasure.

Image: A24; 11 bit studios; Getty Images

We could all use a bit of a break. This weekend we’re diving into Netflix’s beautifully animated sci-fi “Love, Death & Robots,” losing ourselves in surreal “Men” and loving Zelda-like Moonlighter.

Keep Reading Show less
Nick Statt

Nick Statt is Protocol's video game reporter. Prior to joining Protocol, he was news editor at The Verge covering the gaming industry, mobile apps and antitrust out of San Francisco, in addition to managing coverage of Silicon Valley tech giants and startups. He now resides in Rochester, New York, home of the garbage plate and, completely coincidentally, the World Video Game Hall of Fame. He can be reached at


This machine would like to interview you for a job

Companies are embracing automated video interviews to filter through floods of job applicants. But interviews with a computer screen raise big ethical questions and might scare off candidates.

Although automated interview companies claim to reduce bias in hiring, the researchers and advocates who study AI bias are these companies’ most frequent critics.

Photo: Johner Images via Getty Images

Applying for a job these days is starting to feel a lot like online dating. Job-seekers send their resume into portal after portal and a silent abyss waits on the other side.

That abyss is silent for a reason and it has little to do with the still-tight job market or the quality of your particular resume. On the other side of the portal, hiring managers watch the hundreds and even thousands of resumes pile up. It’s an infinite mountain of digital profiles, most of them from people completely unqualified. Going through them all would be a virtually fruitless task.

Keep Reading Show less
Anna Kramer

Anna Kramer is a reporter at Protocol (Twitter: @ anna_c_kramer, email:, where she writes about labor and workplace issues. Prior to joining the team, she covered tech and small business for the San Francisco Chronicle and privacy for Bloomberg Law. She is a recent graduate of Brown University, where she studied International Relations and Arabic and wrote her senior thesis about surveillance tools and technological development in the Middle East.

Latest Stories