PT-2022-8607 · Facebook+4 · Facebook Messenger For Android+6
Published
2022-03-23
·
Updated
2022-03-30
·
CVE-2020-20093
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Facebook Messenger versions 227.0 and prior
Facebook Messenger for Android versions 228.1.0.10.116 and prior
Description
The user interface of the Facebook Messenger app does not properly represent URI messages to the user, resulting in URI spoofing via specially crafted messages. This issue affects multiple messaging platforms, including iMessage, WhatsApp, Instagram, and Facebook Messenger. It is noted that Telegram has patched this issue earlier, and Signal is in the process of fixing it.
Recommendations
For Facebook Messenger versions 227.0 and prior, update to a newer version to resolve the issue.
For Facebook Messenger for Android versions 228.1.0.10.116 and prior, update to a newer version to resolve the issue.
As a temporary workaround, consider disabling the handling of URI messages in the app until a patch is available.
Restrict access to suspicious or unverified messages to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Facebook Messenger
Facebook Messenger For Android
Instagram
Esignal
Telegram
Whatsapp
Imessage