Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data

Summary

A security researcher discovered a broken access control vulnerability within Meta's customer support infrastructure. Meta awarded a bounty of $78,000 for the vulnerability, which could have exposed customer support data.

IFF Assessment

FOE

This is bad news for defenders as a vulnerability was found in a major platform that could have led to a data exposure incident.

Defender Context

This incident highlights the ongoing risks of broken access control vulnerabilities, even in large, well-resourced organizations. Defenders should prioritize thorough access control reviews and implement robust authorization mechanisms to prevent unauthorized data exposure.

Read Full Story →