Technology
Bug in Facebook Messenger exposed users' data
San Francisco, March 8
As Facebook CEO Mark Zuckerberg discussed making his platform more secure, a bug in Facebook Messenger allowed websites to gain access to users' data, including who they have been chatting with, say researchers.
Now fixed by Facebook, the vulnerability in the web version of Messenger allowed any website to expose who you have been messaging, revealed Ron Masas, the researcher with cybersecurity company Imperva, in a blog post late on Thursday.
The researcher reported the vulnerability to Facebook under their responsible disclosure programme and the social media platform mitigated the issue.
In November 2018, Mass and his team discovered a Facebook bug that allowed websites to extract data from users' profiles via cross-site frame leakage (CSFL) which is known as a side-channel attack performed on an end user's web browser.
"Browser-based side-channel attacks are still an overlooked subject. While big players like Facebook and Google are catching up, most of the industry is still unaware," wrote Masas.
Facebook Messenger has over 1.3 billion users globally.
Zuckerberg on Thursday said he is working to make Facebook "privacy-focused" like WhatsApp.
The "privacy-focused platform" will be built around principles like private interactions, encryption, reducing permanence, safety and interoperability.
Now fixed by Facebook, the vulnerability in the web version of Messenger allowed any website to expose who you have been messaging, revealed Ron Masas, the researcher with cybersecurity company Imperva, in a blog post late on Thursday.
The researcher reported the vulnerability to Facebook under their responsible disclosure programme and the social media platform mitigated the issue.
In November 2018, Mass and his team discovered a Facebook bug that allowed websites to extract data from users' profiles via cross-site frame leakage (CSFL) which is known as a side-channel attack performed on an end user's web browser.
"Browser-based side-channel attacks are still an overlooked subject. While big players like Facebook and Google are catching up, most of the industry is still unaware," wrote Masas.
Facebook Messenger has over 1.3 billion users globally.
Zuckerberg on Thursday said he is working to make Facebook "privacy-focused" like WhatsApp.
The "privacy-focused platform" will be built around principles like private interactions, encryption, reducing permanence, safety and interoperability.

37 seconds ago
Trump Administration imposes USD 100,000 annual fee on H-1B visas

1 minute ago
"Startups may face hiring challenges," says former advisor Ajay Bhutoria on USD 100,000 annual fee on H-1B visas

11 hours ago
US revokes sanctions waiver for Iran's Chabahar Port, effective September 29

11 hours ago
Among the worst mayors in the world": Trump slams London Mayor Sadiq Khan

11 hours ago
Things will improve sooner rather than later": NJ Guv Philip Murphy on India-US ties

11 hours ago
India examining implications of US decision to impose sanctions on Chabahar port project

11 hours ago
Sectarian Nationalism and Godmen: Sri Sri Ravishankar attends 75th Birth day of RSS Chief

11 hours ago
I have been to Pakistan and Bangladesh, felt at home': Sam Pitroda stirs row

12 hours ago
Among the worst mayors in the world": Trump slams London Mayor Sadiq Khan

12 hours ago
GOPIO Medical Webinar concludes that Ayurvedic and modern medicine can both be effective for certain diseases

12 hours ago
Trump-Xi hold telephonic conversation, reports Chinese media

12 hours ago
Canadian govt's responsibility to address security concerns: MEA on Khalistani threat to Indian Consulates

12 hours ago
Government assures full support to family of Indian techie shot by US police