Facebook Messenger sticks to a vulnerability that exposes users' contacts
Imperva security team recently announced a security vulnerability on Facebook Messenger that can be exploited by hackers to view the victim's Facebook account list via web browser and iframe (one card in web programming).
According to security experts, with this attack hackers do not get any more data than the user's contact information.
Photo: Threatpost.
Imperva sent a notice about this vulnerability to Facebook and made suggestions for corrections by adjusting the iframe element. However, security experts also added that this is only a temporary treatment but cannot overcome the problem completely.
After receiving information about the vulnerability, Facebook completely deleted the iframe from Messenger.
In recent times, Facebook has been in constant trouble and has been criticized for violating privacy. The most prominent one is the Cambridge Analytica scandal reported in March 2018 and the millions of Facebook users leaked data in October last year.
According to recent information, Facebook is planning to merge Messenger, WhatsApp and Instagram into a unified service. This makes users and professionals worry about the privacy of this social network.
You should read it
- 'Red alert' after the hack targeted Twitter, Facebook removed the feature matching contacts with phone numbers in Messenger
- GIFUR emoji set for Facebook Messenger
- Have you experienced 'My Day' on the Messenger app?
- Facebook launched its first ad for Messenger
- How to know someone blocked you on Facebook Messenger?
- Watch out for the risk of spreading the virus from Facebook Messenger on Windows, MacOS and Linux
- How to use Messenger without Facebook
- How to create snowfall effect on Facebook Messenger
May be interested
- Hackers track iPhone prototypes to exploit vulnerabilitiesprototype iphones are incomplete devices, used for testing and after the research is complete they will be destroyed.
- Guide to get tickets to Samsung's 'Technology-Differentiation Party' event on March 9this is how to register to receive tickets to the online technology banquet at the my dinh stadium on march 9th
- Being hit by a stray bullet, MSI's gaming screen still works normallyon march 4, 2019, a player named eric gan shared an unbelievable twitter story on his twitter account of the stray bullet but his computer gaming screen (msi optix g27c2). can still work normally.
- Gboard's new handwriting recognition feature integrates AI, reducing errors by up to 40%in recent times, google is trying to improve handwriting recognition in gboard - virtual keyboard for ios and android devices, with new ai systems.
- There are 3uTools v2.33, support for downgrade to 64-bit devices and jailbreak iOS 12recently, the 3utools v2.33 version has been released under many new features to increase the user experience.
- Want to receive security updates on Windows 7 next year, users will have to pay at least 50 USD / deviceafter january 14, 2019, to receive security updates, windows 7 users will have to choose to upgrade to windows 8, 8.1 and 10 versions and support or join the service package of extended support program. updates (esu).