logo

Critical XSS Vulnerabilities in Meta Conversion API Enable Zero-Click Account Takeover

ID: 16fa8aad-5c6b-5440-9414-58f216cc09ef

STIX ID: report--16fa8aad-5c6b-5440-9414-58f216cc09ef

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-01-17

Date Updated: 2026-04-22

Author: Divya

...
...

*Researchers disclosed two critical XSS vulnerabilities in Meta's Conversions API Gateway—an improper postMessage origin validation in capig-events.js and a backend stored XSS via unsafe string concatenation—that can enable arbitrary JavaScript execution on Meta domains and potentially compromise ~100 million third‑party deployments, allowing large‑scale account takeover and severe supply‑chain impact.*

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.