Vulnerability Found In Top Messaging Apps Let Hackers Eavesdrop

Its open-source protocol is widely respected, and its encryption model has been adopted by other platforms, including WhatsApp. A recent NPR feature on vulnerabilities within Pentagon communications highlights just how fragile even highly secure systems can be when subjected to targeted attacks. Attacks attributed to groups like Salt Typhoon against major telecommunications providers have highlighted the fragility of the communications infrastructure that underpins governments, businesses, and critical services.

By integrating advanced security protocols and a commitment to privacy, Wire enables organizations and individuals to communicate with confidence, free from the looming threat of data breaches. Users can link their account to desktop applications, which are often less secure than mobile devices. If an attacker compromises a desktop, they gain access not only to stored messages but to ongoing conversations as well.

More recently, security firm Trend Micro uncovered the “Earth Minotaur” threat group using the Moonshine exploit kit to deploy spyware through WeChat, primarily targeting ethnic minority communities. WeChat’s layered defenses, from URL validation to sandboxed browsers, demonstrate a proactive approach to security. To better communicate CVE status, we are updating CVE status labels and descriptions. Additional details on our new process are available on our CVEs and the NVD Process page. Finally, we have updated the NVD Dashboard to accurately report the status of all CVEs and other NVD statistics in real time. A full definition of critical software and a description of our new workflow, including how we will order our processing queue, is available on the NVD website.

Platform

Organizations must rethink their use of third-party apps for sensitive communications. The NSA, in its guidance, has advised government personnel to avoid using Signal for classified or sensitive conversations. While that may not be practical for every business, it’s a strong signal (no pun intended) that not all encrypted apps are created equal. That code, which many apps (including banking, social media, and SMS-ID authentication systems) use as a second layer of security , is the master key. Sharing it, even “because a friend asked for it,” is tantamount to handing over control of the account on a silver platter. Once inside, the criminal can impersonate the victim to request money, access previous conversations, or extend the attack to other services linked to the same number.

vulnerability in messaging

Bug Bounty

The Signal bug, patched in September 2019, allowed an individual to listen in on the recipient’s surroundings, for example, while a Google Duo flaw caused the leak of video packets from unanswered calls. Organizations have until July 22, 2025, to implement necessary mitigations or discontinue use of the affected product to protect their infrastructure from potential compromises. Examining the code snippet above, we can notice that a postMessage call is defined on line 27 as part of an OAuth implementation.

Along with a promise of greater security, it makes companies “warrant-proof” from surveillance efforts. The warning from the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) highlighted vulnerabilities in text messaging systems that millions of Americans use every day. How high-risk individuals can protect their accounts when using apps such as WhatsApp and Signal. Is BestDates Legit? Panda Security specializes in the development of endpoint security products and is part of the WatchGuard portfolio of IT security solutions.

The “generate link preview” feature is known to have privacy and security risks and has led to critical-severity vulnerability problems on Meta’s WhatsApp platform. The research also highlights vulnerabilities in custom protocol handling, where attackers abuse URL validation weaknesses to redirect users to phishing sites or trigger unauthorized actions. Researchers demonstrate how attackers can craft malicious files disguised as legitimate content to achieve remote code execution. Signal is still one of the most secure messaging apps available, but it’s not foolproof. And as recent incidents have shown, even the best tools can be compromised if used carelessly.

That way, whenever a postMessage event is sent or received, the debugger will pause execution, allowing you to inspect the message data, origin, and source. You can examine the call stack to see exactly where the message is being processed and step through the code to identify potential vulnerabilities. A critical security vulnerability in TeleMessageTM SGNL, an enterprise messaging system modeled after Signal, has been actively exploited by cybercriminals seeking to extract sensitive user credentials and personal data. All the rules can be used across dozens of SIEM, EDR, and Data Lake platforms and are aligned with MITRE ATT&CK®. Additionally, each rule is enriched with CTI links, attack timelines, audit configurations, triage recommendations, and more extensive metadata.

The Project Zero researcher also looked at other popular messaging apps such as Telegram and Viber, but she could not find these particular security flaws. She looked at Telegram in August 2020, and Viber was investigated in November last year. Back in November 2018, the very same researcher brought to daylight a similar loophole in WhatsApp – it was affecting not only Android users, but the security flaw was observed on Apple devices too. For communications, marketing, and PR professionals, these technical flaws translate into operational risks. Confidential media strategies, embargoed press releases, and crisis response plans often flow through encrypted messaging apps. But as we’ve seen, the real risk often lies in how these tools are used, not how they’re built.

They will also allow us to stabilize the program while we develop the automated systems and workflow enhancements required for long-term sustainability. As a precaution, security teams should validate patch installation and verify that the fixed version correctly rejects unauthorized synchronization payloads. Organizations must also monitor network traffic for unusual outbound HTTP requests originating from WhatsApp clients, which may indicate exploitation attempts. Follow the Cybersecurity and Infrastructure Security Agency’s Binding Operational Directive (BOD) requirements for cloud service security, including multi-factor authentication and robust logging of all synchronization events. The Facebook Messenger bug allowed audio calls to connect before the call was answered, while similar issues were discovered affecting both the JioChat and Mocha messaging services. In most cases, the vulnerabilities enabled unauthorized personnel to listen in on a call recipient without requiring any interaction from said recipient.

  • When asked to summarize the contents of the blog, SearchGPT follows the malicious instructions from the comment, compromising the user.
  • President Trump downplayed the event, characterizing it as a minor “glitch” and emphasizing the administration’s overall effectiveness.
  • CISA has issued an urgent warning regarding two critical vulnerabilities in TeleMessage TM SGNL that threat actors are currently exploiting in active attack campaigns.
  • The administration, while acknowledging the error, maintained that no classified information was compromised.

In the case of WhatsApp, phone numbers of all contacts, device data, usage patterns, group memberships , profile pictures, status messages, IP addresses, location data, and even payment information (where available) are systematically collected. This data can be used to reconstruct social and professional networks, internal relationship maps within a company, travel habits, and even organizational hierarchies. As security expert Luis Corrons pointed out, a careful attacker would perform the scan slowly and across many IP addresses , blending in with normal traffic and evading detection. The discovery also revealed that around half of the numbers leaked in the massive Facebook scraping of 2021 were still active on WhatsApp, demonstrating that phone numbers, in practice, function as a near-permanent identifier. Thanks to this weakness, researchers demonstrated that it was possible to query more than 100 million phone numbers per hour through WhatsApp’s infrastructure, ultimately enumerating some 3.500 billion active accounts in 245 countries. The system responded to an enormous number of requests from a single source, when the reasonable course of action would have been to reject or limit them.

Additionally, we can also notice that the postMessage data includes the OAuth token, which may be exchanged for a session token later once it reaches the parent window. Your browser’s built-in developer tools can also be deployed to trace back postMessage calls. This method is particularly useful for discovering message handlers that might be hidden in third-party scripts or dynamically loaded code.

CISA has classified both vulnerabilities as actively exploited threats, though the agency notes that their potential use in ransomware campaigns remains unknown at this time. CISA has issued an urgent warning regarding two critical vulnerabilities in TeleMessage TM SGNL that threat actors are currently exploiting in active attack campaigns. PostMessage vulnerabilities can lead to numerous issues, such as DOM-based cross-site scripting and information disclosure. Understanding the full application context with the aim to learn how to weaponize this vulnerability type is key.

However, those that do not meet the criteria above will be categorized as “Lowest Priority – not scheduled for immediate enrichment.” This will allow us to focus on CVEs with the greatest potential for widespread impact. While CVEs that do not meet these criteria may have a significant impact on affected systems, they generally do not present the same level of systemic risk as those in the prioritized categories. The “CVE-Modified” feed  will be much greater in size than normal for the eight-day period following the update process. If you have processes that use this file, prepare to receive a larger file for this period of time. If you use the API, you should also expect larger results for CVE records during this time period. While the vuln schema is changing to reflect these additions, existing processes will not be impacted by this change.

You would suffer from  significant challenges and limitations like inefficiency in work, limited access to information and reduced global connectivity and isolation. Even though all of the vulnerabilities have been patched by the app developers, hackers would still be able to exploit the loophole if the targeted devices are running an older version of the apps. It is also possible that further research would discover more security issues that may be currently in use by hackers. Making sure you have high-end antivirus software installed on all your connected devices and that you regularly update your apps and OS is a must should you want to avoid cyber criminals from having a way into your personal life. Signal’s security flaw was patched in September 2019, and the rest of the messaging apps were fixed more recently in the second half of 2020.

Faced with this sense of vulnerability, many organizations have turned, almost instinctively, to consumer messaging apps as a quick fix to “secure” internal communications. The majority of the research was done on ChatGPT 4o, but OpenAI is constantly tuning and improving their platform, and has since launched ChatGPT 5. The researchers have been able to confirm that several of the PoCs and vulnerabilities are still valid in ChatGPT 5, and ChatGPT 4o is still available for use based on user preference. Prompt injection is a known issue with the way that LLMs work, and, unfortunately, it will probably not be fixed systematically in the near future.

Memories are shared between conversations and considered by the LLM before each response. It is also possible to have a memory about the type of response you want, which will be taken into account whenever ChatGPT responds. TeleMessage is similar to the Signal App but allows for the archiving of chats for compliance purposes.

The embedded browser components in these applications often lag behind official releases, potentially exposing users to known vulnerabilities that remain unpatched. WeChat’s file processing system, designed to enhance user experience through file previews and content extraction, creates significant security exposure when handling untrusted content. Security engineers can also leverage Uncoder AI, an IDE and co-pilot for detection engineering, which is now enhanced with a new AI Chat Bot mode and the MCP tools support. Many of the phishing attacks that compromise Signal accounts rely on social engineering. Teaching employees how to spot suspicious links, question unexpected group invites, and verify QR codes can prevent many of these attacks before they start.

This critical security weakness stems from improper configuration of the Spring Boot Actuator component, which inadvertently exposes a sensitive heap dump endpoint accessible via the /heapdump URI path. Untrusted Types is a browser extension that helps identify DOM XSS vulnerabilities by monitoring dangerous sinks in real-time. When enabled, it tracks data flow from sources (including postMessage event handlers) to sinks, such as innerHTML, and alerts you when untrusted data reaches a dangerous location.

On June 17, 2026, the National Vulnerability Database (NVD) deployed an expansion to its vulnerability assessment metrics and data schema. Furthermore, the NVD will also include “affected” information as defined in the CVE Record Format. This chain of events effectively enables remote code execution (RCE) or content spoofing, which could be leveraged to drop payloads ranging from credential-stealing scripts to ransomware. Organizations and individual users are strongly urged to apply vendor-supplied mitigations by September 23, 2025, or to discontinue use until secure patches are available. The security flaws, which required little technical skill to exploit, have all since been patched. This recommendation underscores the severity of the vulnerabilities and the potential impact on organizational security posture.

By indexing some test websites to Bing, we were able to extract their static tracking links and use them to bypass the url_safe check, allowing our links to be fully rendered. The Bing tracking links cannot be altered, so a single link cannot extract information that we did not know in advance. Our solution was to index a page for every letter in the alphabet and then use those links to exfiltrate information one letter at a time. For example, if we want to exfiltrate the word “Hello”, ChatGPT would render the Bing links for H, E, L, L, and O sequentially in its response.