Facebook Messenger Desktop App Arbitrary File Read

  1. Attacker sends a malicious link to unknown victim
  2. Victims open Spam section and Clicks the link
  3. Using <webview> we load an internal file
  4. With <webview>.executeJavaScript(code) we steal it’s content




