HT TECH wants to start sending you push notifications. Click allow to subscribe

Facebook bug allowed hackers to access users’ personal information including Likes and interests

Facebook says it discovered the issue in May and has already fixed the vulnerability.

By: MARCIA SEKHOSE
Updated on: Nov 14 2018, 19:11 IST
The entrance sign to Facebook headquarters is seen in Menlo Park, California, on Wednesday, October 10, 2018. (REUTERS)

A researcher at cyber security firm Imperva discovered vulnerability in Facebook's search feature that could allow hackers gain access to sensitive user information such as interests, likes and even friends.

Researcher Ron Masas describes this vulnerability as cross-site request forgery (CSRF) which allows any malicious website to remotely collect information from a user's profile on Facebook.

You may be interested in

Mobiles Tablets Laptops
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
16% OFF
Samsung Galaxy S24 Ultra
  • Titanium Black
  • 12 GB RAM
  • 256 GB Storage
₹113,000₹134,999
Buy now
Samsung Galaxy S23 Ultra 5G
  • Green
  • 12 GB RAM
  • 256 GB Storage
₹104,999
Check details
Vivo X100 Pro 5G
  • Asteroid Black
  • 16 GB RAM
  • 512 GB Storage
₹89,999
Check details
39% OFF
Acer Aspire 5 A515 57G Laptop
  • Gray
  • 16 GB RAM
  • 512 GB SSD
₹54,990₹89,999
Buy now
37% OFF
Acer Swift Go SFG14 41 NX KG3SI 002 Laptop
  • Pure Silver
  • 8 GB RAM
  • 512 GB SSD
₹49,990₹78,999
Buy now
17% OFF
Acer Aspire 3 A315 24 NX KDESI 004 Laptop
  • Silver
  • 8 GB RAM
  • 512 GB SSD
₹35,700₹42,999
Buy now
36% OFF
Asus VivoBook 15 X515JA BQ322WS Laptop
  • Transparent Silver
  • 8 GB RAM
  • 512 GB SSD
₹32,200₹49,999
Buy now
33% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹26,999₹39,999
Buy now
47% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹19,998₹38,000
Buy now
33% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹19,389₹28,999
Buy now
Honor Pad X9
  • Gray
  • 4 GB RAM
  • 128 GB Storage
₹16,998
Check details

The bug required users (logged in on Facebook) to visit a malicious website and click anywhere. This would trigger the bug and open a small pop-up or a new browser tab with Facebook's search page. Hackers could then remotely execute any search query.

Also read: Looking for a smartphone? To check mobile finder click here.

A video demonstrating how the hack works shows a pop-up window where the attackers type in the questions. For example, the question for if the person likes running will come with a yes or no reply according to their information on Facebook.

This bug can be used to extract information from the user's friends as well. Masas explains how they could find out different kinds of information possible through this bug. Some of the examples given include finding out whether a user took photos at certain locations, has friends from any specific country, or they've written a post with a specific text.

He further points out this bug could have affected smartphone users more. "This is especially dangerous for mobile users, since the open tab can easily get lost in the background, allowing the attacker to extract the results for multiple queries, while the user is watching a video or reading an article on the attacker's site," he explained.

Ankush Johar, Director at Infosec Ventures explained, "Although CSRF flaws have a big prerequisite to work that the user must be logged in to the website while he/she visits the infected page, what makes the Facebook vulnerability risky is, unlike other websites, most of the users are always logged into Facebook in their browsers thus putting everyone at massive risks. Moreover, it's not known that since how long this vulnerability has existed and has been exploited in the wild."

The bug was reported to Facebook and fixed as well earlier this May.

In a statement to The Verge, Facebook said, "We've fixed the issue in our search page and haven't seen any abuse. As the underlying behavior is not specific to Facebook, we've made recommendations to browser makers and relevant web standards groups to encourage them to take steps to prevent this type of issue from occurring in other web applications."

Facebook has been hit hard by a spate of major security breaches this year. Earlier this year, personal information of over 80 million Facebook users was accessed by a UK-based research consultancy Cambridge Analytica.

In October this year, Facebook said hackers had gained access to private messages of nearly 120 million Facebook accounts. Most of these details have already been published on the dark web.

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 14 Nov, 19:10 IST

Sale

Mobiles Tablets Laptops
4% OFF
Samsung Galaxy S24 Ultra
  • Titanium Black
  • 12 GB RAM
  • 256 GB Storage
₹129,999₹134,999
Buy now
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
13% OFF
Xiaomi 14
  • Matte Black
  • 12 GB RAM
  • 512 GB Storage
₹69,999₹79,999
Buy now
10% OFF
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹80,590₹89,900
Buy now
33% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹26,999₹39,999
Buy now
38% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹34,000
Buy now
28% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹17,999₹24,999
Buy now
11% OFF
Samsung Galaxy Tab S9 5G 256GB
  • Graphite
  • 8 GB RAM
  • 256 GB Storage
₹96,999₹108,699
Buy now
38% OFF
Acer Aspire 3 A315 24 NX KDESI 004 Laptop
  • Silver
  • 8 GB RAM
  • 512 GB SSD
₹32,790₹52,999
Buy now
27% OFF
Infinix INBook X1 Neo XL22 Laptop Intel Celeron Quad Core 8 GB 256 GB SSD Windows 11
  • Blue
  • 4 GB RAM
  • 128 GB SSD
₹21,990₹29,990
Buy now
36% OFF
Infinix INBook X1 Pro Laptop
  • Black
  • 8 GB RAM
  • 256 GB SSD
₹44,990₹69,999
Buy now
29% OFF
Asus VivoBook 15 X515JA EJ522TS Laptop
  • Grey
  • 8 GB RAM
  • 512 GB SSD
₹44,689₹62,889
Buy now