Skip to main content
  1. Home
  2. Social Media
  3. News

Facebook is paying cash rewards if you find vulnerabilities in third-party apps

Add as a preferred source on Google

The recent Cambridge Analytica scandal rocked Facebook, prompting the company to examine more closely where its masses of user data ends up and how it’s utilized.

As part of those efforts, the social networking giant this week announced it’s expanding its bug bounty program to include third-party apps and websites that let people use their Facebook accounts to log in.

Recommended Videos

The company says it’s focusing on the access tokens that are uniquely generated for the specific user and app during login.

“The user decides what information the token and app can access as well as what actions can be taken … [but] a token can potentially be misused,” Dan Gurfinkel, Facebook security engineering manager, explained in a post announcing the expanded program.

Gurfinkel said it will pay at least $500 to anyone who spots vulnerabilities that involve “improper exposure of Facebook user access tokens.” The more serious the issue, the greater the amount Facebook will pay, though it makes no mention of a cap.

He added that Facebook is using the program in an effort to create a clear channel for people to report any issues they come across, “and we want to do our part to protect people’s information, even if the source of a bug is not in our direct control.”

Once an issue has been confirmed by Facebook’s own researchers, it will contact the app or website developer to help them fix their code, and they’ll be suspended from the platform until the issue has been resolved.

“We will also automatically revoke access tokens that could have been compromised to prevent potential misuse, and alert those we believe to be affected,” Gurfinkel said.

The security engineering manager pointed out that Facebook will only accept reports “if the bug is discovered by passively viewing the data sent to or from your device while using the vulnerable app or website.” In other words, researchers are not allowed to “manipulate any request sent to the app or website from your device, or otherwise interfere with the ordinary functioning of the app or website in connection with submitting your report.”

If a flaw is reported by two people working independently of each other, the payment goes to the person who submits the report first. And if the researcher is feeling generous and would like to donate the bounty to charity, Facebook will double the value of the donation.

The expansion of its bug bounty program comes four months after Facebook launched the Data Abuse Bounty Program, another consequence of the damaging Cambridge Analytica scandal in which a third-party app helped to harvest the data of up to 87 million Facebook users for political gain, which led to big questions over the way the social networking company handled user data.

The Data Abuse Bounty program rewards users who discover and report any app or service connected to Facebook that misuses data, specifically, where “a Facebook platform app collects and transfers people’s data to another party to be sold, stolen, or used for scams or political influence,” the company said.

Facebook described its Data Abuse Bounty Program as an industry first.

Trevor Mogg
Contributing Editor
Not so many moons ago, Trevor moved from one tea-loving island nation that drives on the left (Britain) to another (Japan)…
X’s creator payouts are changing, and original content is the new currency
The platform is replacing Revenue Sharing with a program designed to reward creators who actually make something.
X Twitter on iPhone

X is changing the rules for creators yet again. This time, the platform wants to put less emphasis on simply generating engagement and more on actually making something original. X is replacing its controversial Creator Revenue Sharing program with a new initiative called Original Content Rewards, which will officially launch on September 8, 2026. The existing Revenue Sharing program will continue paying participating creators through September 7, after which the new system takes over.

X wants to reward creators, not engagement farmers

Read more
Snapchat’s Spotlight algorithm now favors human-made videos over AI-generated ones
Snapchat is taking a firm stance against AI slop.
Snapchat-App-Store-open-on-iPhone

If you've been uploading fully AI-generated videos on Snapchat in hopes of earning rewards, it might be time to rethink your strategy. Snapchat has announced changes to Spotlight that prioritize authentic, original creativity over content created entirely by artificial intelligence. The company says its recommendation system will now favor videos made by real creators, while fully AI-generated submissions will no longer qualify for monetization.

So what's changing on Spotlight?

Read more
LinkedIn is crowdsourcing its fight against AI slop
The company is rolling out a new button that lets you flag posts that seem AI generated.
LinkedIn seems like AI slop button

LinkedIn has a serious AI slop problem, and it's now turning to its own users to help fix it. The platform is rolling out a new button that lets users flag posts they suspect were generated by AI. It plans to use that feedback to fine-tune the system that decides how much reach a post gets outside a user's own network, based on how AI-generated it appears.

The announcement comes shortly after an analysis by Pangram found that more than forty percent of long-form LinkedIn posts are fully AI-generated, and it suggests that the reach-trimming measures the company rolled out earlier this year haven't been enough on their own.

Read more