Critical XSS Vulnerabilities in Meta Conversion API Enable Zero-Click Account Takeover
ID: 16fa8aad-5c6b-5440-9414-58f216cc09ef
STIX ID: report--16fa8aad-5c6b-5440-9414-58f216cc09ef
Feed Name: GBHackers
Threat Score
*Researchers disclosed two critical XSS vulnerabilities in Meta's Conversions API Gateway—an improper postMessage origin validation in capig-events.js and a backend stored XSS via unsafe string concatenation—that can enable arbitrary JavaScript execution on Meta domains and potentially compromise ~100 million third‑party deployments, allowing large‑scale account takeover and severe supply‑chain impact.*
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
