The research also highlights vulnerabilities in custom protocol handling, where attackers abuse URL validation weaknesses to redirect users to phishing sites or trigger unauthorized actions. Instant messaging (IM) applications like WhatsApp, Telegram, WeChat, and QQ have become the “digital arteries” of modern society, facilitating communication for billions of users worldwide. It is worth noting that not all of the observed behaviors here are necessarily undisclosed sharing. Undisclosed sharing occurs when data we observed being shared from our static and/or dynamic analysis was not disclosed in the privacy disclosures we analyzed.
To make matters worse, misuse of these SDKs may also contribute to the misrepresentation of security and privacy assurances to consumers as articulated in various disclosures, including privacy policies, terms of service, and marketing materials. Prior research has demonstrated how attackers can exploit mobile push notifications to spam users with advertisements (Liu et al., 2019), launch phishing attacks (Xu and Zhu, 2012), and even issue commands to botnets (Ahmadi et al., 2016; Lee et al., 2014; Hyun et al., 2018). Other studies have revealed additional security issues with PNSs that can result in the loss of confidentiality (i.e., user messages get exposed to unauthorized parties) and integrity (i.e., users receive malicious messages from unauthorized parties) (Chen et al., 2015). Of the popular secure messaging apps that we identified, 20 of 21 apps relied on FCM to deliver push notifications to users. One exception among those apps was Briar messenger, which prompted the user to enable unrestricted battery usage, allowing the app to poll for new messages in the background. (Several other apps in our dataset also prompted us to enable unrestricted battery usage, however, those apps still relied on FCM.) Since our study focuses on FCM, we excluded Briar and analyzed only those applications that relied on FCM to deliver push notifications.
Nsfas Cautions Students Against Misinformation Regarding Application Deadlines And Funding Claims
WeChat’s mini-programs, used by over 1.2 billion users, operate in a dual-thread architecture. JavaScript logic and rendering layers are isolated, preventing cross-layer privilege escalation. For example, rendering-layer APIs like insertVideoPlayer cannot access high-risk functions such as saveFile, reducing the impact of cross-site scripting (XSS) vulnerabilities, researchers said.
Signal App Clone Telemessage Vulnerability May Leak Passwords; Hackers Exploiting It
Table 4 enumerates the data types that we searched for during our analysis of Android apps. Google defines and uses these data types to populate the information presented to users in the form of privacy labels in the app’s listing on Google Play Store (Google, 2023d). At the time of publication, the remaining 6 app developers to whom we disclosed our findings had not replied; discussions are ongoing with several companies regarding how they should fix the identified issues.
The “generate link preview” feature is known to have privacy and security risks and has led to critical-severity vulnerability problems on Meta’s WhatsApp platform. The FBI says that the attack was far broader than the CALEA system and that the hackers are still accessing telecom networks. This month, the Biden administration said at least eight telecommunications infrastructure companies in the U.S., and possibly more, had been broken into by Chinese hackers. The CISA released a list of best security practices for smartphone users on Thursday, with specific tips for iPhone and Android owners. Silvanovich adds that similar bugs likely remain undiscovered in mainstream communication apps. She looked only at one-to-one calling, for example, and the iOS group FaceTime vulnerability indicates that group calling may have its own slate of flaws.
In the realm of data sovereignty, the use of global services also means that information can end up stored in jurisdictions with very different access laws , or even laws that contradict local regulations. This opens the door both to intelligence gathering by third-party states and to complex legal battles over which legislation applies to each piece of information. Initially, Trump tried to downplay the incident, claiming that no classified or national security-relevant information was shared, and his team accused the magazine of having a political agenda. However, under pressure, The Atlantic decided to publish the group’s full contents so that the public could assess the seriousness of the matter, also revealing disparaging remarks about European allies that had already surfaced at other summits. CISA has issued an urgent warning regarding two critical vulnerabilities in TeleMessage TM SGNL that threat actors are currently exploiting in active attack campaigns. Critical remediation steps include disabling or restricting access to the /heapdump endpoint, limiting exposure of all Actuator endpoints unless explicitly required, and upgrading to supported Spring Boot versions with secure defaults.
Attacks attributed to groups like Salt Typhoon against major telecommunications providers have highlighted the fragility of the communications infrastructure that underpins governments, businesses, and critical services. Faced with this sense of vulnerability, many organizations have turned, almost instinctively, to consumer messaging apps as a quick fix to “secure” internal communications. Government has promoted the strategy of shifting the burden of software security away from individuals, small businesses, and local governments and onto the organizations that are most capable and best-positioned to reduce risks (The White House, 2023). Cybersecurity and Infrastructure Security Agency (CISA) and 17 U.S. and international partners published an update in August 2023 to joint guidance for implementing secure-by-design principles (Cybersecurity and Infrastructure Security Agency (2023), CISA). The final phase of our analysis involved comparing the claims that app developers made in their privacy disclosures to the ground truth that we observed from our dynamic and static analysis. Therefore, we focused on the 11 app developers that we observed including personal information in the push notifications sent via Google’s FCM (§ 5).
For example, apps may list the data types (e.g., names, phone numbers, identifiers) collected and shared with third parties. As with privacy policies, these privacy labels are required by the Google Play Store’s terms of service to be thorough and complete (Google, 2023d). However, Google states in their guidelines that “transferring user data to a ‘service provider”’ should not be disclosed as data sharing in the app’s privacy labels (Google, 2023d), limiting their scope and potential utility.
Thanks to this weakness, researchers demonstrated that it was possible to query more than 100 million phone numbers per hour through WhatsApp’s infrastructure, ultimately enumerating some 3.500 billion active accounts in 245 countries. The system responded to an enormous number of requests from a single source, when the reasonable course of action would have been to reject or limit them. As a precaution, security teams should validate patch installation and verify that the fixed version correctly rejects unauthorized synchronization payloads.
- But in hackers’ hands, he says, the tools could potentially be used “to surveil communications and metadata for lots of people. And it seems like the hackers’ focus is primarily Washington, D.C.”
- The famous phrase “I joined the wrong chat” went from a joke to a global example of the recklessness of discussing military secrets in an encrypted chat without formal controls.
- A critical security vulnerability in TeleMessageTM SGNL, an enterprise messaging system modeled after Signal, has been actively exploited by cybercriminals seeking to extract sensitive user credentials and personal data.
- On the technical side, it’s essential to keep your devices protected with up-to-date antivirus software and operating systems , and to be wary of any unexpected links or files, even if they come from a known contact (their account may also have been compromised).
One study analyzed 30 different third-party PNS SDKs embedded in 35,173 Android apps and found that 17 https://theasiatalks.com/ SDKs contain vulnerabilities to the confidentiality and integrity of push messages, which an attacker can exploit by running a malicious app on the victim’s device (Chen et al., 2015). Similarly, Lou et al. performed a security and privacy analysis of the twelve most popular PNSs and compared their behavior in 31,049 apps against information practices disclosed in the privacy policies of those PNSs (Lou et al., 2023). They found that out of twelve third-party PNSs, six PNSs collect in-app user behavior and nine collect location information, often without awareness or consent of app users. Although app developers could, in theory, implement their own push notification service, this is usually impractical as it requires the app to continually run as a background service, thereby reducing battery life. Instead, most mobile app developers rely on operating system push notification services (OSPNSs), including Firebase Cloud Messaging (FCM) for Android or Apple Push Notification Service (APNS) for iOS devices (Apple, 2023). FCM and other PNSs facilitate push notifications via an SDK the developer adds to their application.
This data can be used to reconstruct social and professional networks, internal relationship maps within a company, travel habits, and even organizational hierarchies. But in hackers’ hands, he says, the tools could potentially be used “to surveil communications and metadata for lots of people. And it seems like the hackers’ focus is primarily Washington, D.C.” She recommends getting 2FA messages through an app like Google Authenticator or Authy or by using a physical security key to verify access. In full end-to-end encryption, tech companies make a message decipherable only by its sender and receiver — not by anyone else, including the company. Along with a promise of greater security, it makes companies “warrant-proof” from surveillance efforts.
“I find interaction-less bugs to be the most interesting class of vulnerabilities just because they’re so useful to attackers,” Silvanovich says. Operators can deploy content filtering and AI-driven anomaly detection to flag phishing attempts. However, end-user awareness campaigns remain critical, as smishing often bypasses technical defenses.
As depicted in Table 2, of the 8 apps that utilized the end-to-end encryption (e2e) strategy, only 4 (Facebook Messenger, Telegram, Session, and KakaoTalk) did not leak any personal information to Google via FCM. The remaining 4 (Snapchat, SafeUM, YallaChat, and LINE) still leaked metadata, including user identifiers (3 apps) and names (3 apps). Android uses a system component that is part of Google Play Services to receive push messages sent by FCM, which it then passes to the appropriate app. Optionally, the client app can also query additional information from the app server (4) in response to a received push notification. One of the issues with the Conversation Injection technique is that the output from SearchGPT appears clearly to the user, which will raise a lot of suspicion.
A 2014 PEW survey found that 70% of Americans are concerned about government surveillance and 80% about surveillance by corporations (Madden, 2014). In response to these concerns, more and more consumers have begun using secure messaging apps to protect their communications based on the promises of privacy made by these apps. Hundreds of millions of users now use apps like Signal or Telegram, believing these apps to protect their privacy. These applications are entrusted with a vast array of confidential user data, from personal conversations to potentially-sensitive multimedia content, thereby placing a significant emphasis on their ability to make good on their promises of privacy and security. We are unaware of any substantial changes in Android 13 and 14 that would have a material impact on our observed findings.
Scotland bans WhatsApp for official use, leading a movement towards secure, transparent government communication with platforms like Wire. “I think it’s really incumbent on software developers and these companies to have much better privacy and security by default,” Hong says. As agencies work to oust the hackers, the FBI called for Americans to embrace tight encryption — an about-face, Galperin says, after years of insisting that law enforcement agencies need a “back door” to access communications.
In an age where these data breaches pose significant risks to organizational integrity and individual privacy, Wire Secure Messenger emerges as a leading solution for safeguarding sensitive communications. Utilizing state-of-the-art end-to-end encryption, Wire ensures that only authorized users can access messages, reducing interception risks. Its open-source architecture fosters transparency and allows security audits, further enhancing trust in its security measures.
The correct term is “spillage,” and the term applies regardless of severity.An earlier version also incorrectly said a recent Pentagon memo about Signal went out before the leak to a reporter in a chat about bombing Houthi sites in Yemen. In the military, sending classified data over insecure channels is called “spillage”; it can be a career ender for a military officer. The memo continues, “Russian professional hacking groups are employing the ‘linked devices’ features to spy on encrypted conversations.” It notes that Google has identified Russian hacking groups that are “targeting Signal Messenger to spy on persons of interest.” In alerts sent to affected individuals, WhatsApp recommended urgent steps, including a full device factory reset, alongside updating both the WhatsApp app and the underlying operating system to the latest versions. True digital safety requires not just encryption, but also user awareness, platform transparency, and adaptive regulation.
In environments where state secrets or defense information are handled, these types of solutions have approvals from organizations like NATO and government certifications , as well as external audits that validate their design and implementation. It’s not just a matter of technology, but of demonstrating, with documentation and evidence, that the most demanding standards are met. The main lesson from this episode is that we should treat our phone number like a password, not a trivial piece of information . Configuring WhatsApp so that only contacts see your profile picture and information text, avoiding posting your primary phone number on public websites, and using a specific number for ads or business inquiries are small steps that significantly reduce your exposure.
Some apps, such as Signal, send a push notification with no data (aside from the fields that Google sets; see Figure 4). This push notification tells the app to query the app server for data, the data is retrieved securely by the app, and then a push notification is populated on the client side with the unencrypted data. In these cases, the only metadata that FCM receives is that the user received some message or messages, and when that push notification was issued. Achieving this requires sending an additional network request to the app server to fetch the data and keeping track of identifiers used to correlate the push notification received on the user device with the message on the app server.


