{"id":116199,"date":"2020-11-20T08:58:41","date_gmt":"2020-11-20T05:58:41","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/facebook-patches-a-messenger-bug-that-allowed-others-to-snoop-on-your-calls\/"},"modified":"2020-11-20T08:58:41","modified_gmt":"2020-11-20T05:58:41","slug":"facebook-patches-a-messenger-bug-that-allowed-others-to-snoop-on-your-calls","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/facebook-patches-a-messenger-bug-that-allowed-others-to-snoop-on-your-calls\/","title":{"rendered":"#Facebook patches a Messenger bug that allowed others to snoop on your calls"},"content":{"rendered":"<p>&#8220;<strong>#<a href=\"https:\/\/buradabiliyorum.com\/en\/category\/social-mediaa\/\" data-internallinksmanager029f6b8e52c=\"1\" title=\"Social Media\" target=\"_blank\" rel=\"noopener\">Facebook<\/a> patches a Messenger bug that allowed others to snoop on your calls<\/strong>&#8221;<br \/>\n<img decoding=\"async\" src=\"https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2020\/11\/brett-jordan-xdBNTAdqU3A-unsplash-1-796x597.jpg\" \/><\/p>\n<div>\n                            We often joke around that hackers or government agencies are listening to our calls. Facebook just patched a bug that would\u2019ve allowed anyone to snoop on your calls on Messenger.<\/p>\n<p>The bug was found by\u00a0Google Project Zero researcher\u00a0<span><a rel=\"nofollow noopener noreferrer\" target=\"_blank\" href=\"https:\/\/twitter.com\/natashenka\">Natalie Silvanovich<\/a> last month, and it affected Messenger\u2018s Android users. To start the attack, the hacker would have to initiate a call and send a specially crafted invisible message. Then they could listen to your audio, even if you don\u2019t pick up the call.\u00a0<\/span><\/p>\n<p>Thankfully, this vulnerability was only exploitable in special circumstances and required specific tools. For instance,\u00a0<span>both the attacker and the victim would need to have been logged in to Messenger for Android. In addition to that, the victim also needed to be logged into Messenger through a web browser.\u00a0<\/span>What\u2019s more, the attacker would need permission to call the victim\u00a0 \u2014 meaning, they\u2019d have to already be on the victim\u2019s friend list.<\/p>\n<p>Last year, <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">App<\/a>le fixed the bug that let your contacts eavesdrop on you through FaceTime.\u00a0<span>Silvanovich said after this exploit was found, she began to research other apps. Till now, she\u2019s <a rel=\"nofollow noopener noreferrer\" target=\"_blank\" href=\"https:\/\/www.wired.com\/story\/facebook-messenger-bug-bounty\/\">managed to find bugs<\/a> in other communication apps such as <a rel=\"nofollow noopener noreferrer\" target=\"_blank\" href=\"https:\/\/bugs.chromium.org\/p\/project-zero\/issues\/detail?id=1943&amp;q=signal%20label:Finder-natashenka&amp;can=1\">Signal<\/a>, <a rel=\"nofollow noopener noreferrer\" target=\"_blank\" href=\"https:\/\/bugs.chromium.org\/p\/project-zero\/issues\/detail?id=2064&amp;q=mocha%20label:Finder-natashenka&amp;can=1\">Mocha<\/a>, and JioChat; all of them have been patched.\u00a0<\/span><\/p>\n<p>Facebook revealed details about this bug as a part of the blog on the 10th anniversary of its bug bounty program. The company said it has paid $11.7 million to security researchers for 6,900 accepted bug reports out of more than 130,000 submitted.<\/p>\n<p>Last month, the social network unveiled a new loyalty program, called Hacker Plus, to further incentivize bug sleuths discovering vulnerabilities in Facebook\u2019s platforms.<\/p>\n<p>You can read the full technical description of the vulnerability <a rel=\"nofollow noopener noreferrer\" target=\"_blank\" href=\"https:\/\/bugs.chromium.org\/p\/project-zero\/issues\/detail?id=2098\">here<\/a>.<\/p>\n<\/p><\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong>\n<\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more like this article, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/technology\/\" target=\"_blank\" rel=\"noopener noreferrer\">Technology category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/thenextweb.com\/security\/2020\/11\/20\/facebook-patches-a-messenger-bug-that-allowed-others-to-snoop-on-your-calls\/\" target=\"_blank\" rel=\"noopener noreferrer\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;#Facebook patches a Messenger bug that allowed others to snoop on your calls&#8221; We often joke around that hackers or government agencies are listening to our calls. Facebook just patched a bug that would\u2019ve allowed anyone to snoop on your calls on Messenger. The bug was found by\u00a0Google Project Zero researcher\u00a0Natalie Silvanovich last month, and&#8230;<\/p>\n","protected":false},"author":1,"featured_media":116200,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/img-cdn.tnwcdn.com\/image\/tnw?filter_last=1&fit=1280,640&url=https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2020\/11\/brett-jordan-xdBNTAdqU3A-unsplash-1.jpg&signature=56a9dd00605f77f49ac2a85e4c3d3984","fifu_image_alt":"","footnotes":""},"categories":[18],"tags":[4974,74846,80776],"class_list":["post-116199","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology","tag-facebook","tag-hacker","tag-messenger"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/116199","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=116199"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/116199\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/116200"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=116199"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=116199"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=116199"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}