15/12/2022
My post was removed for some time due to an incomplete fix. 10 months later, I'm now allowed to share again!
Learn how a page could trick their visitors into launching internal deeplinks via the app
https://www.ash-king.co.uk/blog/abusing-Facebooks-call-to-action-to-launch-internal-deeplinks
A page is able to add a `Call to action` (CTA) button against their page. This tool is designed for user engagement allowing a page admin to redirect visitors to their website, app, inbox, WhatsApp etc. It is possible for a page admin to abuse this feature and launch Facebook's internal deeplinks. i...