Technology
Bug in Facebook Messenger exposed users' data
San Francisco, March 8
As Facebook CEO Mark Zuckerberg discussed making his platform more secure, a bug in Facebook Messenger allowed websites to gain access to users' data, including who they have been chatting with, say researchers.
Now fixed by Facebook, the vulnerability in the web version of Messenger allowed any website to expose who you have been messaging, revealed Ron Masas, the researcher with cybersecurity company Imperva, in a blog post late on Thursday.
The researcher reported the vulnerability to Facebook under their responsible disclosure programme and the social media platform mitigated the issue.
In November 2018, Mass and his team discovered a Facebook bug that allowed websites to extract data from users' profiles via cross-site frame leakage (CSFL) which is known as a side-channel attack performed on an end user's web browser.
"Browser-based side-channel attacks are still an overlooked subject. While big players like Facebook and Google are catching up, most of the industry is still unaware," wrote Masas.
Facebook Messenger has over 1.3 billion users globally.
Zuckerberg on Thursday said he is working to make Facebook "privacy-focused" like WhatsApp.
The "privacy-focused platform" will be built around principles like private interactions, encryption, reducing permanence, safety and interoperability.
Now fixed by Facebook, the vulnerability in the web version of Messenger allowed any website to expose who you have been messaging, revealed Ron Masas, the researcher with cybersecurity company Imperva, in a blog post late on Thursday.
The researcher reported the vulnerability to Facebook under their responsible disclosure programme and the social media platform mitigated the issue.
In November 2018, Mass and his team discovered a Facebook bug that allowed websites to extract data from users' profiles via cross-site frame leakage (CSFL) which is known as a side-channel attack performed on an end user's web browser.
"Browser-based side-channel attacks are still an overlooked subject. While big players like Facebook and Google are catching up, most of the industry is still unaware," wrote Masas.
Facebook Messenger has over 1.3 billion users globally.
Zuckerberg on Thursday said he is working to make Facebook "privacy-focused" like WhatsApp.
The "privacy-focused platform" will be built around principles like private interactions, encryption, reducing permanence, safety and interoperability.
11 hours ago
'Stranger things have happened,' Trump on Mexican cartels
11 hours ago
Lieutenant Governor Aruna K. Miller Celebrates Opening of New Biotech Lab Building 4MLK in Downtown Baltimore
11 hours ago
'Watching announcements very carefully...': Union Minister Hardeep Puri on Trump's remarks on energy
11 hours ago
Trump revokes security clearances of former officials who signed letter on Hunter Biden's laptop
12 hours ago
US President Donald Trump signs order establishing Department of Government Efficiency
12 hours ago
US President Donald Trump announces plans to impose 25% tariffs on Mexico, Canada from February 1
12 hours ago
US President Trump issues executive order to withdraw from WHO
12 hours ago
Trump administration sued on day 1 over order aiming to end birthright citizenship
13 hours ago
Tillotama says ‘Paatal Lok 2’ team offering her a role was a joke until her first reading
13 hours ago
'Chhaava': Rashmika Mandanna's first look as Maharani Yesubai screams royal
13 hours ago
Saif Ali Khan Stabbing Case: Security beefed up at actor's Bandra home
13 hours ago
Ayushmann Khurrana reveals phone conversation on wife Tahira Kashyap's birthday
13 hours ago
‘Kantara: Chapter 1’ makers are shooting a grand war sequence for the film