After an investigation conducted by cybersecurity researcher Natalie Silvanovich, the expert discovered vulnerabilities in many apps with 10M+ http://www.thecityceleb.com/branded/what-is-daterhapsody-7-day-breakdown/ installs on Google Play that accept incoming calls. The affected applications include hugely popular apps such as Facebook Messenger, Signal, Google Duo, JioChat, and Mocha. At the Black Hat security conference in Las Vegas on Thursday, Silvanovich is presenting her findings about remote eavesdropping bugs in ubiquitous communication apps like Signal, Google Duo, and Facebook Messenger, as well as popular international platforms JioChat and Viettel Mocha. All of the bugs have been patched, and Silvanovich says that the developers were extremely responsive about fixing the vulnerabilities within days or a few weeks of her disclosures.
News Type
The vulnerability—and the fact that it required no taps or clicks at all on the part of the victim—captivated Natalie Silvanovich. Security engineers can also leverage Uncoder AI, an IDE and co-pilot for detection engineering, which is now enhanced with a new AI Chat Bot mode and the MCP tools support. With Uncoder, defenders can instantly convert IOCs into custom hunting queries, craft detection code from raw threat reports, generate Attack Flow diagrams, enable ATT&CK tags prediction, leverage AI-driven query optimization, and translate detection content across multiple platforms.
Real-time monitoring of signaling traffic can reveal suspicious SMS behavior, such as abnormal OTP interception patterns or silent SMS flooding. These are the first line of defense, inspecting signaling traffic and blocking malicious or unauthorized SMS-related requests. Additionally, WeChat’s mini-program architecture separates rendering and logic layers into isolated threads, preventing cross-layer privilege escalation attacks. The platform employs strict validation for sensitive operations, restricting debugging functions and enforcing HTTPS-only protocols with domain validation for configuration changes.
Top 10 Phishing Kits Used By Hackers To Launch Cyberattacks (july 20-26,
They emphasized that these attacks do not exploit flaws in Signal’s underlying encryption technology but instead rely on deceiving users into revealing their credentials or other sensitive information. The encrypted messaging platform Signal has vehemently denied accusations of vulnerabilities within its system, following a Pentagon advisory cautioning against its use. The advisory, distributed internally, alleged that Russian hacking groups were exploiting the app’s “linked devices” feature to compromise encrypted conversations. This warning came on the heels of a high-profile incident where top US national security officials inadvertently included a journalist in a Signal group chat discussing a potential military strike against Houthi targets in Yemen. Signal, in a series of posts on X (formerly Twitter), refuted these claims, clarifying that the advisory’s reference to a “vulnerability” was not related to any flaws in its core encryption technology, but rather to the risk of phishing scams targeting its users.
Signal And Other Video Chat Apps Found To Have Some Major Security Flaws
The selection of messaging apps based on their privacy claims is not only a prudent approach for users prioritizing the confidentiality of their communications, but also a legally-grounded strategy, reflecting the enforceable nature of such assertions. When companies publicly assert their services’ privacy and security features, these claims become material representations that can significantly influence consumer choices. (and various state consumer protection laws), businesses in the U.S. are prohibited from materially misrepresenting their practices to consumers. The Federal Trade Commission (FTC) and state attorneys general actively monitor and pursue companies that fail to uphold their privacy promises (regardless of whether they are made in privacy policies (Commission, 2021) or marketing materials (Commission, 2024)). This enforcement protects consumers and reinforces the message that privacy and security assertions are material representations that have legal consequences and can affect consumer choices.
But Silvanovich says that other flaws came from design decisions specific to each service related to when and how it sets up calls. A Signal spokesman said the Pentagon memo is not about the messaging app’s level of security, but rather that users of the service should be aware of what are known as “phishing attacks.” That’s when hackers try to gain access to sensitive information through impersonation or other deceptive tricks. The main goal was to trigger a push notification so that the resulting payload sent from Google’s FCM server to our test device could be recorded (connection 3 in Figure 2). We installed each app on two devices and triggered push notifications by sending messages from one device to another. On the recipient’s Pixel 3a device, we recorded the push notification contents as they were received by the app using the instrumented methods.
- However, sophisticated attackers could potentially leverage this corruption as a primitive for achieving code execution on targeted devices.
- When companies publicly assert their services’ privacy and security features, these claims become material representations that can significantly influence consumer choices.
- In this post, we’ll explore the major data breaches that affected messaging apps between 2020 and 2024, analyze what went wrong, and extract lessons to build safer communication platforms — without sacrificing convenience.
We determined that 8 apps employed an end-to-end encryption strategy to prevent privacy leakage to Google via FCM. In this strategy, when the user launches the app for the first time, the app provisions a keypair and does a secure key exchange between the user’s device and the app’s server. The app will then develop a session key that it can use to decrypt messages from the server. For instance, in the context of a messaging app, a sender device may send a message to the app server (1), which then sends a push notification request to FCM (2).

Comments are closed