Instagram Investigates Reported Vulnerability Allowing Access to Private Content
ID: c7adbdcd-2738-5566-9c19-9a2d796cc0bd
STIX ID: report--c7adbdcd-2738-5566-9c19-9a2d796cc0bd
Feed Name: GBHackers
A researcher reported a server-side authorization failure in Instagram's mobile web interface that could return private account content (full-resolution photos, captions) via unauthenticated GET requests with specific mobile headers. The researcher provided timestamped video, PoC scripts, network logs, screenshots, and correspondence; Meta initially misclassified the issue as CDN caching, then patched affected accounts within days without explicit acknowledgement or clear root-cause analysis, raising concerns about disclosure handling and residual risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
