PT-2022-8607 · Facebook+4 · Facebook Messenger For Android+6

Published

2022-03-23

·

Updated

2022-03-30

·

CVE-2020-20093

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Facebook Messenger versions 227.0 and prior Facebook Messenger for Android versions 228.1.0.10.116 and prior
Description The user interface of the Facebook Messenger app does not properly represent URI messages to the user, resulting in URI spoofing via specially crafted messages. This issue affects multiple messaging platforms, including iMessage, WhatsApp, Instagram, and Facebook Messenger. It is noted that Telegram has patched this issue earlier, and Signal is in the process of fixing it.
Recommendations For Facebook Messenger versions 227.0 and prior, update to a newer version to resolve the issue. For Facebook Messenger for Android versions 228.1.0.10.116 and prior, update to a newer version to resolve the issue. As a temporary workaround, consider disabling the handling of URI messages in the app until a patch is available. Restrict access to suspicious or unverified messages to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-20093

Affected Products

Facebook Messenger
Facebook Messenger For Android
Instagram
Esignal
Telegram
Whatsapp
Imessage