Little Doctor: Hackers who wish to gain access to popular chat applications to use users' cameras and audio can do so very easily using a worm published online.
At the moment it is still a zero day which means the security flaw has not been patched. 
The framework, dubbed “Little Doctor,” is a super weapon that can compromise JavaScript-based chat apps. So many popular chat apps are at risk due to their architecture. Services developed in Electron, or that contain an embedded webview, are in a very difficult position.
It should be noted that Rocket Chat released a patch within 13 hours of the disclosure, and Ryver within a day. The Slack app also uses WebViews, but they appear to be secure.
Australian hacker Shubham Shah and former colleague Matt Bryant developed the framework worm and found an unpatched Microsoft Azure Storage Explorer zero day.
"This worm is cross-platform, and can steal files from any application that has access to the WebRTC APIs, and the Cordova APIs," Moloch said at the Kiwicon hacking conference held in Wellington.
The team disclosed the bug to Microsoft, but after 90 days, they had not received a response.
The trio didn't stop there, finding and demonstrating the exploit in the Rocket Chat and Ryver apps, turning a cross-site scripting attack into remote code execution for the container apps.
View the PoCs and download Little Doctor
The Little Doctor framework is available on GitHub for all security researchers and penetration testers.
