Blog | G5 Cyber Security

Fake Android notifications first Google, then Microsoft affected

Google Hangouts app among Google Android users received spammy messages this week. Cybersecurity researcher Absss Abss identified Android apps that had been careless with their popup notification keys. He found a way to deliver rogue messages by making a specific request to the Firebase Cloud Messaging service interface based on what FCM calls topics. FCM allows a notification to be tagged for delivery to users who are interested in various combinations of topics, and this meant he could easily find a topic specifier that covered all users of any app.”]

Source: https://nakedsecurity.sophos.com/2020/08/28/fake-android-notifications-first-google-then-microsoft-affected/

Exit mobile version