Although app developers could, in theory, implement their own push notification service, this is usually impractical as it requires the app to continually run as a background service, thereby reducing battery life. Instead, golden age souls most mobile app developers rely on operating system push notification services (OSPNSs), including Firebase Cloud Messaging (FCM) for Android or Apple Push Notification Service (APNS) for iOS devices (Apple, 2023). FCM and other PNSs facilitate push notifications via an SDK the developer adds to their application. When a user launches the app for the first time, the SDK registers the device with the PNS by generating a push token (also known as a registration token), which serves as a pseudonymous identifier that tells the push service where to forward the messages.
- We looked specifically at privacy leakage through push notifications that rely on FCM.
- In early 2019, a bug in group FaceTime calls would have let attackers activate the microphone, and even the camera, of the iPhone they were calling and eavesdrop before the recipient did anything at all.
- It required that both the attacker and target be logged into Facebook for Android and that the victim also be logged into Messenger in a web browser or some other way.
News Type
Threema has introduced mitigations after the researchers privately shared their findings. The updates include a new custom protocol named Ibex, which fixes vulnerabilities 2.1 and 2.2. Threema developers also removed compression altogether, a change that fixes vulnerability 3.2. Attacks 1.1 and 1.2 were mitigated by use of better key separation, using a key derivation function. Threema has also added a new check that will allow non-compromised servers to detect the impersonation attacks described in 1.1 and 1.2. The latter is easier to implement privately in the sense that there’s less that can go wrong; the connection is established only after your affirmative consent.
Signal is still one of the most secure messaging apps available, but it’s not foolproof. And as recent incidents have shown, even the best tools can be compromised if used carelessly. Communications leaders must stop thinking of security as someone else’s job and start treating it as a core part of their own.
“Push” is the technology for sending messages from the server-side component of the app (the “app server”) to its client side (the “client app”), even when the user is not actively using the app. Notifications refer to the process of displaying timely information to the user by the app’s user interface (UI) (Basques and Gaunt, 2023). In the context of mobile apps, the application server can send a push message without displaying a notification (i.e., a silent push); an app can also display a notification based on an in-app event without receiving any push messages. We used dynamic analysis to record the contents of a push notification after our device received it from the FCM server. This method then delivers push notification contents to app-specific callback methods (e.g., onMessageReceived), which allow the app to handle and display push messages as notifications to users.
(We elaborate on the specific impact to the user in the Full Attack Vector PoCs section below.) The potential reach of this vulnerability is tremendous, since attackers could spray malicious prompts in comment sections on popular blogs and news sites, compromising countless ChatGPT users. A new class of indirect prompt injection (IPI) attacks targets Google Gemini’s voice assistant, allowing attackers to silently hijack the AI through malicious payloads delivered via everyday messaging apps, including WhatsApp, Slack, Signal, SMS, Instagram, and Messenger. In an age where these data breaches pose significant risks to organizational integrity and individual privacy, Wire Secure Messenger emerges as a leading solution for safeguarding sensitive communications. Utilizing state-of-the-art end-to-end encryption, Wire ensures that only authorized users can access messages, reducing interception risks. Its open-source architecture fosters transparency and allows security audits, further enhancing trust in its security measures. By integrating advanced security protocols and a commitment to privacy, Wire enables organizations and individuals to communicate with confidence, free from the looming threat of data breaches.
Users can link their account to desktop applications, which are often less secure than mobile devices. If an attacker compromises a desktop, they gain access not only to stored messages but to ongoing conversations as well. That’s a serious liability for any organization handling confidential information, be it corporate strategy, crisis communications, or sensitive negotiations. Attacks attributed to groups like Salt Typhoon against major telecommunications providers have highlighted the fragility of the communications infrastructure that underpins governments, businesses, and critical services.
Far-reaching Consequences Of Data Breaches In Communication Tools
Recent data indicates a staggering 150% increase in attack attempts targeting users of these messaging applications over the last quarter alone. This surge underscores the urgent need for effective solutions to protect users and their data from potential breaches. Threema has more than 10 million users, which include the Swiss government, the Swiss army, German Chancellor Olaf Scholz, and other politicians in that country. Threema developers advertise it as a more secure alternative to Meta’s WhatsApp messenger.
Exposure Management
Regulators will continue tightening oversight — pushing for greater transparency, accountability, and user empowerment. Ultimately, breaches often stemmed from weak surrounding systems, not the encryption itself. Panda Security, a WatchGuard Technologies brand, offers the most advanced protection for your family and business.
The implications were so severe that Apple invoked a nuclear option, cutting off access to the group-calling feature entirely until the company could issue a fix. The vulnerability—and the fact that it required no taps or clicks at all on the part of the victim—captivated Natalie Silvanovich. The research also highlights vulnerabilities in custom protocol handling, where attackers abuse URL validation weaknesses to redirect users to phishing sites or trigger unauthorized actions. Researchers demonstrate how attackers can craft malicious files disguised as legitimate content to achieve remote code execution.
