If you look at this question: Firebase one to one chat
You will see in the comment:
It sounds like your application will need to access the address book of the user's phone, which is something Firebase security rules cannot do (since they run on the Firebase server).
Is this true?