[Facebook] Improper blockage/disabling call/video call

An attacker in the Message Group could disable the call/video call feature and remain on Group calls/video calls of the Group even after getting blocked by the Admin of chat.

POC -

An attacker makes a Group call. Either the attacker himself or the Admin removes him from the Group.

Attacker will still be on the call even after getting blocked or remove himself. He can hear and see other people and other people will hear him too.

If the attacker stays in the Group, he can ring individuals in the Group.

As the admin or other members if we try to make a new call to the group, we will be automatically connected to the attackers call. We won't get an option to create a separate call for the group as there is a pre existing call going on.

Timeline -

Reported - Wednesday, February 6, 2019 

Triaged - Wednesday, February 13, 2019

Fixed - Wednesday, October 16, 2019

Rewarded - Thursday, October 24, 2019

Popular posts from this blog

[Google] Access to BGP server + DOM XSS

[Google] YouTube "restconf" Swagger-UI XSS

[Google] Disclose hidden Blogger profile Display name and Profile photo