Facebook has begun rolling out an important update to its Facebook Messenger application on Monday, after it was found the app was susceptible to a security flaw forcing users’ iPhones to place expensive calls automatically - racking up a large bill.
Developer Andrei Neculaesei was first to identify the issue last week, saying scammers use the Uniform Resource Identifier (URI) scheme called ”tel” to trigger a call without a user knowing. Usually clicking on a link containing a phone number will take a user to Safari and then prompt them to confirm the call. However, apps like Facebook Messenger, Google+, Gmail, and FaceTime, make the call without asking the user.