Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2020-20093

Description

The Facebook Messenger app for iOS 227.0 and prior and Android 228.1.0.10.116 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages.

POC

Reference

- http://packetstormsecurity.com/files/166448/RTLO-Injection-URI-Spoofing.html

- https://github.com/zadewg/RIUS

Github

- https://github.com/ARPSyndicate/cvemon

- https://github.com/theguly/stars

- https://github.com/zadewg/RIUS