HT TECH wants to start sending you push notifications. Click allow to subscribe

This Facebook bug exposed Instagram users’ personal emails IDs, birthdays

Thanks to the bug, all this private information could be accessed just by sending the user a direct message (DM). Fortunately, it has been fixed.

By: HT TECH
Updated on: Aug 21 2022, 13:30 IST
A bug discovered by security researcher Saugat Pokharel made Instagram vulnerable and allowed an attacker to easily procure private information. (Pixabay)

While signing up for an Instagram account, the photo and video sharing platform promises that your email ID and birthday will not be visible to others or be public. However, a bug discovered by security researcher Saugat Pokharel made the platform vulnerable and allowed an attacker to easily procure that private information.

The bug has been patched by Facebook after being reported, but it was exploitable by business accounts that were given access to an experimental feature that Instagram was testing.

You may be interested in

Mobiles Tablets Laptops
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
23% OFF
Samsung Galaxy S23 Ultra 5G
  • Green
  • 12 GB RAM
  • 256 GB Storage
₹115,999₹149,999
Buy now
Google Pixel 8 Pro
  • Obsidian
  • 12 GB RAM
  • 128 GB Storage
₹106,998
Check details
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹87,900
Check details
21% OFF
Acer Swift Go SFG14 41 NX KG3SI 002 Laptop
  • Pure Silver
  • 8 GB RAM
  • 512 GB SSD
₹58,990₹74,999
Buy now
39% OFF
Acer Aspire 5 A515 57G Laptop
  • Gray
  • 16 GB RAM
  • 512 GB SSD
₹54,949₹89,999
Buy now
22% OFF
Acer Aspire 3 A315 24 NX KDESI 004 Laptop
  • Silver
  • 8 GB RAM
  • 512 GB SSD
₹33,499₹42,999
Buy now
39% OFF
Asus VivoBook 15 X515JA BQ322WS Laptop
  • Transparent Silver
  • 8 GB RAM
  • 512 GB SSD
₹31,490₹51,990
Buy now
34% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹26,299₹39,999
Buy now
55% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹47,000
Buy now
32% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹19,790₹28,999
Buy now
Honor Pad X9
  • Gray
  • 4 GB RAM
  • 128 GB Storage
₹14,999
Check details

In this particular case, the attack used Facebook’s Business Suite tool, a feature that is available to any Facebook business account. The experimental upgrade, as The Verge explains, meant that if a Facebook business account was linked to Instagram and was included in the test group, the Business Suite tool would show additional information about a person alongside any direct message. This additional information included their erstwhile private email address and birthday details. To get this, all a business user would have to do is to send a direct message to the user on Instagram.

Security researcher Pokharel found that the attack worked on accounts that were set to private and on accounts that were set to not accept DMs from the public. If an account did not have its DMs open, the user would also not receive any notification indicating that their profile may have been viewed.

This is not the first bug Pokharel has spotted on Instagram and reported. Back in August he discovered that Instagram was not actually deleting deleted posts.

Also Read: Instagram kept deleted photos, messages on its servers for more than a year

A Facebook spokesperson told The Verge that this recent bug was accessible for only a very short time as the experiment was started in October. Facebook did not mention how many users had been given access to this experimental feature but they said that it was a “small test”. Facebook added that they have not found any evidence of abuse.

Here’s Facebook’s full statement:

A researcher reported an issue where, if someone was a part of a small test we ran in October for business accounts, personal information of the person they were messaging could have been revealed. This issue was resolved quickly, and we discovered no evidence of abuse. Through our Bug Bounty Program we rewarded this researcher for his help in reporting this issue to us.

According to Pokharel, Facebook engineers fixed the issue within a few hours of being notified about it.

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 19 Dec, 18:57 IST

Sale

Mobiles Tablets Laptops
4% OFF
Samsung Galaxy S24 Ultra
  • Titanium Black
  • 12 GB RAM
  • 256 GB Storage
₹129,999₹134,999
Buy now
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
13% OFF
Xiaomi 14
  • Matte Black
  • 12 GB RAM
  • 512 GB Storage
₹69,999₹79,999
Buy now
11% OFF
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹79,800₹89,900
Buy now
57% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹19,999₹47,000
Buy now
38% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹17,999₹28,999
Buy now
21% OFF
Samsung Galaxy Tab S9 5G 256GB
  • Graphite
  • 8 GB RAM
  • 256 GB Storage
₹88,858₹113,098
Buy now
6% OFF
Apple iPad Pro 11 2022
  • Silver
  • 8 GB RAM
  • 128 GB Storage
₹105,999₹112,900
Buy now
23% OFF
Infinix INBook X1 Neo XL22 Laptop Intel Celeron Quad Core 8 GB 256 GB SSD Windows 11
  • Blue
  • 4 GB RAM
  • 128 GB SSD
₹22,990₹29,990
Buy now
37% OFF
Asus ROG Strix Scar 15 G532LW AZ056T Laptop
  • Black
  • 16 GB RAM
  • 1 TB SSD
₹146,200₹231,990
Buy now
24% OFF
Asus ROG Strix G15 G513RC HN063W Laptop
  • Electro Punk
  • 16 GB RAM
  • 512 GB SSD
₹66,500₹86,990
Buy now
37% OFF
Asus Zenbook 14 OLED UX3402VA KN541WS Laptop
  • Ponder Blue
  • 16 GB RAM
  • 512 GB SSD
₹85,990₹135,990
Buy now
NEXT ARTICLE BEGINS