Facebook has fixed a vulnerability in its Messenger IM chat app, both on the web and mobile versions, that could have allowed attackers to edit or delete any existing message in a conversation.
Check Point researcher Roman Zaikin discovered the issue earlier this month, and Facebook quickly released updates to address the problem before exploits.
According to Zaikin, it's very easy for someone to exploit this vulnerability. The way Facebook Messenger chat works is by linking messages between two users, via Facebook's servers. Each message has a random message_id value, unique to each message.
Zaikin realized that by searching for the facebook.com/ajax/mercury/thread_info.php URL, he could discover the ID of each message.
The only requirement is that the attacker has a way to connect and store the message request. This can be done through proxy servers or by infecting the user's device with malware that will record these message requests and then send them to the server .
Assuming that the attacker has obtained the identity of an IM, Zaikin developed a simple automated attack that would send a message with the same identifier and rewrite the content of the original message.
Since the mobile version of the Messenger app allows users to delete messages, the same automated attack can also be used to delete existing messages.
The attack is extremely dangerous because it allows IM spammers to constantly update their messages with updated malicious URLs, in case authorities shut down their original servers.
Furthermore, since IM chat logs are admissible as evidence in court, an attacker could also modify existing conversations to shift blame to the wrong person or absolve a fraudster of any wrongdoing.
Below you can watch a video from Raikin, showing the Facebook Messenger vulnerability in action.
[su_youtube url=”https://youtu.be/QRksIURxnks” width=”640″ height=”380″]https://www.youtube.com/watch?v=B7o0qA4L4So[/su_youtube]
Finally, it's worth noting that Facebook spoke to Softpedia about a number of details that were left out of the Check Point report. A Facebook spokesperson says that the bug only allowed attackers to change their own messages and that it was temporary until the app could refetch the data to the server. All original messages would still be documented and accessible on other platforms, so there was always a source of truth that would show the messages correctly.
Additionally, users would not be able to insert any content, including links and malware, that would have been blocked in the original messages. Facebook says all messages are still sent through anti-malware and anti-spam filters.

