Skip to main content

Facebook pays $15,000 bounty to close bug that can access any user’s account

A major flaw in Facebook’s account security has been brought to light by a security researcher, who has received a cool $15,000 payout from the social network for his efforts.

Anand Prakash spotted the flaw, which allowed him access to any user’s account on the platform, last month. The bug was related to the Facebook account reset process, which results in the site sending a six-digit PIN to a user’s phone to be used as a temporary password.

Recommended Videos

Usually, the individual resetting an account is granted approximately 10-12 wrong password guesses. Prakash noticed that those security measures were missing from the Facebook beta site for developers, where every single user account is also readily available. Consequently, the bug allowed Prakash to seemingly flood the site with PIN guesses, and hack into any account he wanted.

Instead of exploiting the flaw, however, Prakash notified Facebook through its report vulnerability page. The following day, the social network confirmed that the bug occurred due to a change to the beta page a few days earlier. Although Facebook assures that the flaw was not misused in that time frame, it still felt compelled to pay the $15,000 bug bounty to Prakash.

The resulting award and Facebook’s rapid response in stamping out the bug hints at the major risk involved. It may not have been the most complicated security issue, but it could have resulted in complete chaos if utilized through the site’s main page.

“One of the most valuable benefits of bug bounty programs is the ability to find problems even before they reach production,” Facebook said in a statement to The Verge. “We’re happy to recognize and reward Anand for his excellent report.”

Since its inception, Facebook’s bug bounty program has forked out over $4 million to hackers and security researchers for responsibly disclosing issues in its system.

Saqib Shah
Former Digital Trends Contributor
Saqib Shah is a Twitter addict and film fan with an obsessive interest in pop culture trends. In his spare time he can be…
How to download a video from Facebook
An elderly person holding a phone.

Facebook is a great place for sharing photos, videos, and other media with friends and family. But what if you’d like to download a video to store offline? This means you’d be able to watch the clip on your PC or mobile device, without needing to be connected to the internet. Fortunately, there’s a way to download Facebook videos to your everyday gadgets, although it’s not as straightforward a process as it could be.

Read more
How to undo reposts on TikTok (and why you should)
Undo Repost button on the TIkTok app.

TikTok, like many other social media apps, including Threads, allows its users to repost the content they enjoy to share it with their followers. However, unlike apps such as X, formerly Twitter, which provide clear instructions on how to undo a repost and indicate when it has been successfully undone, TikTok’s process is not as straightforward.

Read more
Instagram shows love to smaller accounts that post original content
Notifications related to Instagram's new algorithm to surface content linked to smaller accounts.

Instagram is starting to show some love to smaller accounts that post original content. The Meta-owned media-sharing platform announced in a blog post on Tuesday that it’s making a number of changes to give more prominence to material posted by “smaller, original content creators” over those with large followings and aggregators of reposted content, which up until now have received greater exposure in recommendations.

The move to give those with smaller followings more reach on Instagram involves making four changes to the current way of doing things, the company said.

Read more