A security researcher has identified bugs in popular mobile apps video conferencing and chat that allowed potential attackers to listen to audio and receive data before the person on the other end picks up the calls. The bugs were discovered by Google Project Zero researcher Natalie Silvanovich and have now been fixed. The apps vulnerable to the bugs were: Signal, Google Duo, Facebook Messenger, JioChat, and Mocha.

The vulnerabilities forced targeted devices to transmit audio and video to attackers' devices without the need to execute code.
“I investigated the call mechanisms of seven video conferencing applications and found five vulnerabilities that allow the caller’s device to force the device of the person receiving the call to transmit audio or video data,” Silvanovich explained.
According to the researcher, even if data transmission (from the person receiving the call to the caller) is unavoidable, at least the person should have answered the call first.
"However, when I looked at the apps, I saw that they allowed transmission in many different ways. Most of them had vulnerabilities that allowed calls to be connected without interaction from the person receiving the call."

The researcher reported one such bug in Signal that was fixed in September 2019.

Similarly, a bug in Google Duo allowed people receiving calls to leak video to the caller over unanswered calls. This bug was fixed in December 2020. A vulnerability in Facebook Messenger that allowed audio calls to connect before the person answered the call was also fixed in November 2020.
Finally, two similar vulnerabilities were discovered in JioChat and Mocha messengers in July 2020, which allowed data to be sent without the user. The bug in JioChat was fixed in July 2020 and Mocha in August 2020.
Silvanovich searched for similar issues in other apps , such as Telegram and Viber, but found nothing.
“The majority of video conferencing apps I investigated had vulnerabilities that allowed audio or video content to be transmitted from the person receiving a call to the caller, without the caller’s consent,” Silvanovich added.
“It is also important to note that I did not test group calling features of these applications , and all of the vulnerabilities reported were found in peer-to-peer calls. This is an area for future work that could uncover additional issues.“.
Source: Bleeping Computer
