HomeSecurityMessenger bug allowed users' calls to be listened to

Messenger bug allowed users' calls to be listened to

A dangerous bug involving Messenger calls was discovered by Project Zero , which immediately reported the vulnerability to Facebook. The Google team was able to identify a bug that allowed hackers to listen in on a call before it even took place, leaving users unable to detect that someone was monitoring them.

Messenger

Social media giant Facebook could be facing a major security threat related to Messenger calls that went undetected for a long time. Malicious actors could use the flaw as a means to listen to users' calls who don't answer while their phones continue to ring.

According to Wired , Facebook's " bug bounty program " is a huge help when it comes to security issues. Teams participating in the program are dedicated to studying the structure and interface for any known or hidden bugs that could compromise user security.

Google's Project Zero bug team recently discovered the bug in Facebook Messenger for Android. Natalie Silvanovich was the first to discover it and immediately notified Facebook.

The Google team received a $60,000 reward for discovering and trying to find a long-undetected bug. Hackers who know how to exploit it can send an invisible message and make a call to the target person and listen to what is happening on the other line, even if the users don't answer the call.

The invisible message contains the means and methods for the malicious user to listen to the other line. Furthermore, the recently discovered bug resembles a security issue in Apple's FaceTime , which appeared in group calls

The bug would only work if the user and the hacker are friends on Facebook or connected on Messenger with authorization from the account owner. However, users who have a lot of friends and accept requests from anyone are more likely to run into a malicious user. This bug would be a problem for users who have a large list of Facebook friends, which makes it difficult to track them.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS