⚡️ Official word from Microsoft on twitter:
We're investigating an issue where users are receiving Test notifications on their mobile devices. Further updates will be provided under the SI TM221041 in your admin center.
Now we have ROUND 2 of such messages, most of us would be getting messages like - "Testing Notifcation from Microsoft to investigate this problem". If yiy watch closely the spelling of Notifation is incorrect. "Notifcation" which definitely makes it more suspicious! This is mostly probably linked to some Firebase exploit.
Many people using Microsoft Teams and Google Hangouts have reported that they have received multiple strange alters in form of push notification on their Android/iOS mobile devices.
The message says
Testing Notifcation from Microsoft to investigate this problem
Clicking on the notification open up the respective App. That's it.
Sequence of events described by users -
- Sudden FCM messages popup on mobile phone.
- Multiple push notifications. 2 reported in many cases.
- Clicking the notification card opens the App.
- App opens normally and does not redirect anywhere, just opens the respective Teams/Hangouts App.
- Message can be ignored and cleared.
There was a recent vulnerability reported for Firebase Cloud Messaging (FCM), allowing to exploit FCM keys stored in APK files in order to broadcast messages to anyone using a Firebase based application. FCM is used by many Apps to deliver push notifications.
These messages seems related and linked to the reported FCM vulnerability.
Though the alert messages seem harmless and can be ignored for now until we get clarification from big giants like Google and Microsoft. Who knows there would be more App being impacted.More Update:1:55 pm, Thursday, 27 August 2020, Greenwich Mean Time (GMT)
⚠️ Some people are now reporting that they are receiving messages "FCM test notificationsss" which seems more suspicious!
There is a Google Hangout support thread that's going on since past two days on the same question: https://support.google.com/hangouts/thread/66799899?hl=en
Microsoft teams reddit page: https://www.reddit.com/r/MicrosoftTeams/comments/ihghrq/test_notification_fcm/
Some users may receive unexpected Test notifications on their Android devicesMicrosoft has published this information in Microsoft 365 admin center --> Service Health.
The Status shows "Service restored", so we can assume there will be no further such messages.
The message reads