Technology
Bug in Facebook Messenger exposed users' data
San Francisco, March 8
As Facebook CEO Mark Zuckerberg discussed making his platform more secure, a bug in Facebook Messenger allowed websites to gain access to users' data, including who they have been chatting with, say researchers.
Now fixed by Facebook, the vulnerability in the web version of Messenger allowed any website to expose who you have been messaging, revealed Ron Masas, the researcher with cybersecurity company Imperva, in a blog post late on Thursday.
The researcher reported the vulnerability to Facebook under their responsible disclosure programme and the social media platform mitigated the issue.
In November 2018, Mass and his team discovered a Facebook bug that allowed websites to extract data from users' profiles via cross-site frame leakage (CSFL) which is known as a side-channel attack performed on an end user's web browser.
"Browser-based side-channel attacks are still an overlooked subject. While big players like Facebook and Google are catching up, most of the industry is still unaware," wrote Masas.
Facebook Messenger has over 1.3 billion users globally.
Zuckerberg on Thursday said he is working to make Facebook "privacy-focused" like WhatsApp.
The "privacy-focused platform" will be built around principles like private interactions, encryption, reducing permanence, safety and interoperability.
Now fixed by Facebook, the vulnerability in the web version of Messenger allowed any website to expose who you have been messaging, revealed Ron Masas, the researcher with cybersecurity company Imperva, in a blog post late on Thursday.
The researcher reported the vulnerability to Facebook under their responsible disclosure programme and the social media platform mitigated the issue.
In November 2018, Mass and his team discovered a Facebook bug that allowed websites to extract data from users' profiles via cross-site frame leakage (CSFL) which is known as a side-channel attack performed on an end user's web browser.
"Browser-based side-channel attacks are still an overlooked subject. While big players like Facebook and Google are catching up, most of the industry is still unaware," wrote Masas.
Facebook Messenger has over 1.3 billion users globally.
Zuckerberg on Thursday said he is working to make Facebook "privacy-focused" like WhatsApp.
The "privacy-focused platform" will be built around principles like private interactions, encryption, reducing permanence, safety and interoperability.
7 hours ago
Tehran to give safe passage to Indian ships in Strait of Hormuz: Iran envoy
7 hours ago
Amid geopolitical fragmentation, India maintains constructive ties across competing blocs
7 hours ago
Khalistani extremism remains serious concern as India and Canada look at stabilising relationship
8 hours ago
US tanker crash in Iraq kills six crew
9 hours ago
Iran is losing military power fast: US
9 hours ago
US fires first precision strike missiles in combat
10 hours ago
Turkey says intercepted ballistic munition from Iran
13 hours ago
West Asia conflict: EAM Jaishankar and Iranian counterpart discuss role of BRICS
13 hours ago
Controversy over Ganesh Kumar’s personal life stirs unease within NSS ranks ahead of polls
14 hours ago
ATA Delegation Invites Maryland Governor and Lt. Governor to the ATA 19th Conference in Baltimore
14 hours ago
Hindu mantras to start the day of six legislative bodies in Arizona
14 hours ago
Adah Sharma to play superhero in ‘Super Velli’
14 hours ago
In poll-bound West Bengal, LPG becoming a political issue
