# Messenger Rooms Bug Bounty Write-up

By [Jane Manchun Wong](<https://wongmjane.com/about>)

Published: 2020-04-24T18:15:00.000Z

Language: en

[Canonical article](<https://wongmjane.com/blog/messenger-rooms-writeup>)

Unrestricted API calls as Messenger Rooms Guest

## [Timeline (TL;DR)](<https://wongmjane.com/blog/messenger-rooms-writeup#timeline>)

- 2019-10-10T11:39:03.000Z — Report Sent
  
  By: Jane Manchun Wong
  
  Status: caution
- 2019-10-10T11:39:03.000Z — Report Triaged
  
  By: Facebook
  
  Status: inform
- 2020-04-08T02:47:00.000Z — Requested for status update
  
  By: Jane Manchun Wong
- 2020-04-15T18:43:19.000Z — Mitigated with a temporary fix
  
  By: Facebook
  
  Status: inform
- 2020-04-21T18:15:29.000Z — Vulnerability Patched
  
  By: Facebook
  
  Status: success
- 2020-04-22T18:28:25.000Z — Bug Bounty Awarded
  
  By: Facebook
  
  Status: success
- 2020-04-24T18:19:30.933Z — Embargo Lifted
  
  Status: success

> **Heads up\!**
> 
> This security vulnerability report was submitted 6 months before Messenger Rooms was released. There might be slight terminology differences, for instance, “Video Meetup Link” and “Messenger Call” at the time are now branded as “Messenger Rooms”

## [Introduction](<https://wongmjane.com/blog/messenger-rooms-writeup#intro>)

Messenger is developing “Video Meetup Link”, a feature that allows anyone to join a Messenger Call through an invite link even without a Facebook account.

This anonymous Messenger call joining is authenticated by creating a special kind of ` User `  named  ` [REDACTED] ` .

Although ` [REDACTED] ` is created for the sole purpose of joining the Messenger Call, this guest user is capable of doing more than what it is supposed to do. For example, (anonymously) creating a “Video Meetup Link” as a video meetup guest user.

The guest user is also capable of other queries, such as browsing Facebook without having a real Facebook account.

` [REDACTED] ` should only be capable of joining the Messenger Call, nothing else. Other operations than joining the call should be unauthorized.

## [Repro Steps](<https://wongmjane.com/blog/messenger-rooms-writeup#repro-steps>)

Supposedly, the only thing a ` [REDACTED] ` can do is join the Messenger Call the guest user is created for. But here, we can create another Messenger Call using the guest user.

From the response of the above request, we can see it is possible to create another Messenger Call Invite Link without a real Facebook account. A ` [REDACTED] ` is not supposed to have that capability.

Other than creating the invite link, ` [REDACTED] ` is also capable of browsing Facebook, when it is supposed to only be able to join the Messenger Call it is created for. It does not bypass the usual privacy checks per se, but ` [REDACTED] ` is not even supposed to be able to browse any content whose privacy setting is set to “Public”. Again, the only job this user has is to join the Messenger Call.

## [Further Comments from Facebook](<https://wongmjane.com/blog/messenger-rooms-writeup#fb-response>)

After this security vulnerability has been resolved, I reached out to Facebook for further comments. Facebook’s Security Team told me via Facebook Tech Comms Manager [Alexandru Voica](<https://x.com/alexvoica>) with the following statement:

> The issue you found was in an early test of Messenger video chat links, which we’ve fixed in Messenger Rooms. To address the issue, we made the permission checks on our API more restrictive. People who join a Room call without a Facebook or Messenger account will only be able to access the video chat. They will not be able to access Facebook or Messenger without creating an account first. Rooms links can only be created by people with Facebook or Messenger accounts, and soon through WhatsApp and Instagram too. As always, we appreciate you submitting the report to our bug bounty program and helping us strengthen the security of our products\!
