Google Research Pinpoints Security Soft Spot in Multiple Chat Platforms
#1
Information 
Quote:Google Project Zero researcher Natalie Silvanovich outlined what she believes is a common theme when it comes to serious vulnerabilities impacting leading chat platforms. The research, published Tuesday, identifies a common denominator within chat platforms, called “calling state machine”, which acts as a type of dial tone for messenger applications.
 
Silvanovich warns that this common “calling state machine” mechanism used by Signal, Google Duo, Facebook Messenger, JioChat and Mocha is ripe for abuse today and has been the common thread in a litany of past critical bugs.
 
For example, past bugs in the messaging apps Signal, Google Duo and Facebook Messenger, which had allowed threat actors to spy on users through unauthorized transmission of audio or video, were tied to configuration errors in the “calling state machine”. Those settings, Silvanovich said, are key to setting up simple app consent between user connections.
 
In all, Silvanovich identified five logic vulnerabilities in the signalling state machines of seven video conferencing applications that “could allow a caller device to force a callee device to transmit audio or video data.”

While all of the vulnerabilities she identified have already been fixed, the prevalence of the errors in how state machines are implemented in these types of apps–as well as a lack of awareness of this type of bug–means that they will continue to pose a threat, Silvanovich said.

Read more: https://threatpost.com/google-research-p...ms/163175/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Mozilla Thunderbird 147.0.2 & 140.7.2esr
Thunderbird Versio...harlan4096 — 16:52
qBittorrent 5.1.4
qBittorrent 5.1.4:...harlan4096 — 16:48
Mozilla Firefox Browser 126.0.1
Firefox 147.0.4 al...harlan4096 — 16:47
Notepad++ 8.9.2
Notepad++ v8.9.2 R...harlan4096 — 16:46
Sandboxie 1.17.0 / 5.72.0
Sandboxie 1.17.0 /...harlan4096 — 16:45

[-]
Birthdays
Today's Birthdays
avatar (39)TranoTymn
Upcoming Birthdays
avatar (38)showercurtains
avatar (49)PeterWhink
avatar (46)dimaWeami
avatar (38)Michaelaburi
avatar (46)dpascoal
avatar (51)Ronaldduh
avatar (39)legalgauch
avatar (44)Baihu

[-]
Online Staff
There are no staff members currently online.

>