https://developer.android.com/about/versions/12/behavior-cha...
Edit: if the notification is sent by an attacker, does the attacker get access to firebase metrics as well? (Guessing they at least contain info about how many people opened the app)
Or did not many people get it? Could I be targeted, along with the others in this thread?
If the attacker really intended to send the notification to everyone (or even 10%), wouldn't that very likely get the attention of Airbnb, and then they'd know about the issue and be able to mitigate it?
Edit: assuming everyone got it, this seemed much more likely to be a mistake, to me. For example, someone working at Airbnb was testing something and accidentally did it in prod instead of dev. Otherwise, why not camouflage this as something more innocent, like an ad for Airbnb, saying something generic like "Check out our listings near you"?
Now Airbnb knows to change their key or something if possible, and I'll be very suspicious of any notifications from any app in the future, especially Airbnb.
It's like climate change: let's all drive full speed into a wall, while tinkering with the stereo system of the car.
There is zero reason why any dev (or worse external dev team) should have access to prod secrets, or the ability to push out via prod. (unless someone cocked up the config for the dev/staging push notification tooling, again requires a level of access)
At the very least they might have wanted to understand a baseline for how many people will open a notification just to dig into the app and try to disable future notifications, regardless of how annoying the text in the notification was.