HomeSecurityBugs in Messenger, Signal, Google Duo allowed spying

Bugs in Messenger, Signal, Google Duo allowed spying

A security researcher has identified bugs in popular mobile apps video conferencing and chat that allowed potential attackers to listen to audio and receive data before the person on the other end picks up the calls. The bugs were discovered by Google Project Zero researcher Natalie Silvanovich and have now been fixed. The apps vulnerable to the bugs were: Signal, Google Duo, Facebook Messenger, JioChat, and Mocha.

Google Duo

The vulnerabilities forced targeted devices to transmit audio and video to attackers' devices without the need to execute code.

“I investigated the call mechanisms of seven video conferencing applications and found five vulnerabilities that allow the caller’s device to force the device of the person receiving the call to transmit audio or video data,” Silvanovich explained.

According to the researcher, even if data transmission (from the person receiving the call to the caller) is unavoidable, at least the person should have answered the call first.

"However, when I looked at the apps, I saw that they allowed transmission in many different ways. Most of them had vulnerabilities that allowed calls to be connected without interaction from the person receiving the call."

Signal

The researcher reported one such bug in Signal that was fixed in September 2019.

Messenger

Similarly, a bug in Google Duo allowed people receiving calls to leak video to the caller over unanswered calls. This bug was fixed in December 2020. A vulnerability in Facebook Messenger that allowed audio calls to connect before the person answered the call was also fixed in November 2020.

Finally, two similar vulnerabilities were discovered in JioChat and Mocha messengers in July 2020, which allowed data to be sent without the user. The bug in JioChat was fixed in July 2020 and Mocha in August 2020.

Silvanovich searched for similar issues in other apps , such as Telegram and Viber, but found nothing.

“The majority of video conferencing apps I investigated had vulnerabilities that allowed audio or video content to be transmitted from the person receiving a call to the caller, without the caller’s consent,” Silvanovich added.

“It is also important to note that I did not test group calling features of these applications , and all of the vulnerabilities reported were found in peer-to-peer calls. This is an area for future work that could uncover additional issues.“.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS