Premium mobile phones can be unlocked using a photograph of the owner, research has shown. Top-of-the-range devices from Samsung, Motorola and Oppo had their facial recognition security feature easily spoofed, Which? said. A total of 133 models were tricked by the consumer group into opening with a 2D picture, including the Samsung Galaxy S25 (£800), Oppo Find X9 Pro (£1,099), Motorola Razr 50 Ultra (£999) and Oppo Find X9 (£899). Other models from Asus, Fairphone, Honor, HMD, Nokia, Nothing, OnePlus, Realme, Vivo and Xiaomi also failed the test. All were Android devices. Apple’s Face ID remained secure. The three newest Google Pixel models and Samsung Galaxy S26 series were not spoofed by a photo. Basic 2D face-check systems work by using the front camera to take a picture and comparing it with the image saved on set-up. If it is similar enough, the phone unlocks. Apple, Google and some Android phone makers use a 3D face-check system that maps the shape of your face by projecting thousands of invisible dots on to it to measure the depth, contours and structure. That makes it harder to spoof using a photo. Some phones using 2D technology warn users about the weakness of the system. However, Motorola, OnePlus and Nothing were highlighted for failing to do so. Which? said warnings should be prominent during the set-up process rather than “buried” in terms and conditions or another link. The group said Motorola had released 27 phones since 2022 that could be unlocked with a 2D photo or by someone resembling the owner. Lisa Barber, tech editor at Which?, said: “It almost seems unbelievable that phone cameras could be fooled by a printed photo — and yet they can be.” Which? recommends switching to a fingerprint or six-digit PIN if there is a 2D unlocking