A bug during a Facebook test recently exposed the personal information like email addresses and birthdays of Instagram users, the media reported.
Saugat Pokharel, an experienced bug hunter from Nepal, discovered the bug.
The attack used Facebook's Business Suite tool, available to any Facebook business account, reports The Verge.
Pokharel found that the attack worked on accounts that were set to private and accounts that were set to not accept DMs from the public.
"If an account did not accept DMs, the user potentially would not receive any notification indicating their profile may have been viewed," the report said on Friday.
Facebook patched the vulnerability after being reported.
According to a Facebook spokesperson, the bug was only accessible for a short period of time during a small test.
"A researcher reported an issue where, if someone was a part of a small test we ran in October for business accounts, personal information of the person they were messaging could have been revealed," the company spokesperson was quoted as saying.
"This issue was resolved quickly, and we discovered no evidence of abuse. Through our Bug Bounty Program we rewarded this researcher for his help in reporting this issue to us".
Pokharel earlier found another bug in Instagram and awarded a $6,000 bug bounty payout. He found that Instagram retained photos and private direct messages on its servers long after he deleted them.
The company fixed the bug and allowed Pokharel to disclose the bug issue.
--IANS
na/
(Only the headline and picture of this report may have been reworked by the Business Standard staff; the rest of the content is auto-generated from a syndicated feed.)
You’ve reached your limit of {{free_limit}} free articles this month.
Subscribe now for unlimited access.
Already subscribed? Log in
Subscribe to read the full story →
Smart Quarterly
₹900
3 Months
₹300/Month
Smart Essential
₹2,700
1 Year
₹225/Month
Super Saver
₹3,900
2 Years
₹162/Month
Renews automatically, cancel anytime
Here’s what’s included in our digital subscription plans
Exclusive premium stories online
Over 30 premium stories daily, handpicked by our editors


Complimentary Access to The New York Times
News, Games, Cooking, Audio, Wirecutter & The Athletic
Business Standard Epaper
Digital replica of our daily newspaper — with options to read, save, and share


Curated Newsletters
Insights on markets, finance, politics, tech, and more delivered to your inbox
Market Analysis & Investment Insights
In-depth market analysis & insights with access to The Smart Investor


Archives
Repository of articles and publications dating back to 1997
Ad-free Reading
Uninterrupted reading experience with no advertisements


Seamless Access Across All Devices
Access Business Standard across devices — mobile, tablet, or PC, via web or app
)