Security News > 2020 > November > Facebook Messenger bug allowed Android users to spy on each other

Facebook Messenger bug allowed Android users to spy on each other
2020-11-19 14:59

Facebook fixed a critical flaw in the Facebook Messenger for Android messaging app that allowed callers to listen to other users' surroundings without permission before the person on the other end picked up the call.

Facebook Messenger for Android has been installed on more than 1 billion Android devices according to the app's official Play Store page.

Silvanovich found the issue on version 284.0.0.16.119 of Facebook Messenger for Android last month.

As per Facebook's explanation, this bug "Could have allowed a sophisticated attacker logged in on Messenger for Android to simultaneously initiate a call and send an unintended message type to someone logged in on Messenger for Android and another Messenger client."

Facebook awarded Silvanovich with a $60,000 bounty for finding and disclosing this Messenger for Android bug.


News URL

https://www.bleepingcomputer.com/news/security/facebook-messenger-bug-allowed-android-users-to-spy-on-each-other/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Facebook 30 2 44 52 19 117
Android 4 0 17 2 0 19