Facial recognition security fooled by photo on majority of Android phones A major security investigation has revealed that six in 10 Android smartphones can be tricked into unlocking using a simple 2D printed photograph. The UK’s consumer association Which? conducted extensive lab testing on 208 mobile phone models since October 2022, finding that a staggering 133 devices (64% of those tested) failed to distinguish between a real human face and a flat image. The flaw primarily affects devices that rely on standard 2D facial recognition systems. Unlike more sophisticated technology, these cameras capture a flat image that lacks depth perception, making it impossible for the software to distinguish between a high-resolution photo and a living person consistently. The failure rate has fluctuated significantly over recent years. While 53% of phones failed in 2023, that figure spiked to 72% in 2024, before settling at 63% in 2025. The list of vulnerable handsets includes high-end flagship models that retail for over £1,000, such as the Motorola Razr 50 Ultra and the Oppo Find X9 Pro. Samsung’s former flagship range, the Galaxy S25 series, also fell victim to the photo spoofing test. However, there are signs of improvement in the latest hardware. Apple’s Face ID and the new Samsung Galaxy S26 series successfully passed the tests by using 3D mapping technology, which projects thousands of invisible dots to create a complex depth map of the user’s face. Which? raised particular concern regarding manufacturers that fail to provide “adequate” warnings about these security limitations during device setup. Motorola, OnePlus, and the newer brand Nothing were singled out for either burying warnings in terms and conditions or failing to provide them prominently. “In this age of cutting-edge technology, it seems unbelievable that phone cameras could be fooled by a printed photo – and yet they