Nowadays mobile phones have been widely used, and Android is one of the most popular mobile operating system. The security issue of Android has caught great concerns among mobile users and researchers. In this paper, we study the vulnerabilities related of phone cameras. Specifically, we discover and present several camera-based attacks including the basic camera attack and advanced passcode inference attacks. We implement these attacks on real phones (with anti-virus software installed) and demonstrate the feasibility and effectiveness of the attacks. Furthermore, a lightweight defense scheme is proposed to secure phones against these attacks.