Facebook awards $10K for finding bug in its Android app
By
Biju Kumar
New Delhi: A security researcher has found a vulnerability in the download feature of Facebooks Android app that could be exploited to launch remote code execution (RCE) attacks. The social networking giant awarded the researcher $10,000 for finding the bug.
Facebook’s Android app uses two methods of downloading files from a group — a built-in Android service called DownloadManager and a second method called Files Tab.
Security researcher Sayed Abdelhafiz discovered a path traversal flaw in the second method.