Vulnerabilities in Signal, Google Duo and Facebook messenger allowed eavesdropping
User's privacy and security are at huge risk due to these vulnerabilities present in leading apps.
Google's researcher reported that these vulnerabilities in the above-listed apps allowed hackers to eavesdrop without getting detected. The vulnerability allowed hackers to listen to the surrounding audio even before the call was picked up.
The vulnerable apps include Google Duo, Signal, JioChat, Facebook Messenger, and Mocha messaging apps. The vulnerability brings a huge breach of privacy and security to the table which will haunt users for a very long period.
The bug in Signal allowed attackers to send the connect message from the caller device to the callee without any user interaction. The Google Duo bug was a race condition allowing the callees to leak unanswered calls video packets to the caller to connect the audio calls before it was answered.
Facebook Messenger’s bug could allow an attacker to initiate a call and send out a custom message to any target after logging in to the app. The bugs in Mocha and JioChat allowed sending JioChat audio and Mocha audio/video.
However, all of these vulnerabilities are patched as of now, NPAV recommends users to regularly update all the apps on their devices. Updates often contain security patches that will ensure the proper security of your devices.
Install NPAV on your devices to keep them protected from all kinds of cyberattacks. Use NPAV and join us on a mission to secure the cyber world.
- Other (42)
- Ransomware (128)
- Events and News (26)
- Features (45)
- Security (434)
- Tips (79)
- Google (22)
- Achievements (9)
- Products (33)
- Activation (7)
- Dealers (1)
- Bank Phishing (42)
- Malware Alerts (195)
- Cyber Attack (222)
- Data Backup (11)
- Data Breach (81)
- Phishing (139)
- Securty Tips (1)
- Browser Hijack (16)
- Adware (15)
- Email And Password (67)
- Android Security (56)
- Knoweldgebase (38)
- Botnet (15)
- Updates (3)
- Alert (71)
- Hacking (57)
- Social Media (7)
- vulnerability (54)
- Hacker (31)
- Spyware (8)
- Windows (6)
- Microsoft (21)
- Uber (1)
- YouTube (1)
- Trojan (2)
- Website hacks (3)
- Paytm (1)
- Credit card scam (1)
- Telegram (3)
- RAT (5)
- Bug (3)
- Twitter (2)
- Facebook (7)
- Banking Trojan (5)
- Mozilla (2)
- COVID-19 (5)
- Instagram (2)
- NPAV Announcement (6)
- IoT Security (1)
- Deals and Offers (1)
- Cloud Security (8)
- Offers (5)
- Gaming (1)
- FireFox (2)
- LinkedIn (2)
- WhatsApp (4)
- Amazon (1)
- DMart (1)
- Payment Risk (4)
- Occasion (3)
- firewall (1)
- Cloud malware (2)
- Cloud storage (2)
- Financial fraud (8)
- Impersonation phishing (1)
- DDoS (4)
- Smishing (2)
- Whale (0)
- Whale phishing (3)
- WINRAR (2)
- ZIP (2)