Facebook Messenger: Alert for Hundreds of Millions of People

Facebook Messenger compromise

Facebook Messenger is one of the largest messaging platforms in the world, and hundreds of millions of people are targeted by an extremely important alert that came officially from the Facebook company. More precisely, those from Facebook admitted that an extremely serious problem of Facebook Messenger was discovered in the version of the application for Android phones, and through it the entire Facebook account of the victim could be compromised.

Facebook Messenger had this very serious problem in the Rooms function, which was created by the Facebook company to offer people an alternative to Zoom. Unfortunately, the vulnerability that existed for Facebook Messenger allowed an attacker to compromise the victim's Android phone through an invitation sent for Rooms, by initiating an audio/video call, but for completion it was necessary to accept the invitation, or the call.

Facebook Messenger: Alert for Hundreds of Millions of People

Facebook Messenger had a vulnerability that could not be exploited remotely without the victim interacting with what is being sent, or accepting the call, but even so, the problem was very serious. After the victim interacts with the invitation or notification, the attacker exploits Facebook Messenger to gain access to the victim's Facebook account, and from that point he could see everything that was published on it, but also publish statuses as if he were the victim .

Facebook Messenger had such a serious problem that the exploitation could be done even without the Android phone requiring unlocking to activate the exploit, and those from Facebook recognized the problem. The computer security researcher from whom everyone learned about the problem notified Facebook about the vulnerability in Facebook Messenger, and the company rewarded him with the sum of 3000 dollars, the minimum for what he discovered.

Facebook Messenger has the problem solved now, but users with Android phones need to have the latest update installed to be protected against a possible attack.