Riccardo Padovani 1/26/2025

Responsible disclosure: retrieving a user's private Facebook friends.

Read Original

This technical article explains a security vulnerability where an attacker could retrieve a user's private Facebook friend list by signing up for Instagram with the victim's email address. It details the flaw's mechanism, involving the linking of accounts and features available before email confirmation. The post includes the responsible disclosure timeline to Facebook and the resulting $3000 bounty award.

Responsible disclosure: retrieving a user's private Facebook friends.

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week

2
Designing Design Systems
TkDodo Dominik Dorfmeister 2 votes
3
Introducing RSC Explorer
Dan Abramov 1 votes
5
Fragments Dec 11
Martin Fowler 1 votes
6
Adding Type Hints to my Blog
Daniel Feldroy 1 votes
7
Refactoring English: Month 12
Michael Lynch 1 votes
9