[Facebook] Improper blockage/disabling call/video call
An attacker in the Message Group could disable the call/video call feature and remain on Group calls/video calls of the Group even after getting blocked by the Admin of chat.
POC -
An attacker makes a Group call. Either the attacker himself or the Admin removes him from the Group.
Attacker will still be on the call even after getting blocked or remove himself. He can hear and see other people and other people will hear him too.
If the attacker stays in the Group, he can ring individuals in the Group.
As the admin or other members if we try to make a new call to the group, we will be automatically connected to the attackers call. We won't get an option to create a separate call for the group as there is a pre existing call going on.
Timeline -
Reported - Wednesday, February 6, 2019
Triaged - Wednesday, February 13, 2019
Fixed - Wednesday, October 16, 2019
Rewarded - Thursday, October 24, 2019