logo

Six Hours, $4500: The Short Life and Quick Death Of A Facebook Bug

ID: bf0f5f2c-2e58-55de-96ed-29a96119b330

STIX ID: report--bf0f5f2c-2e58-55de-96ed-29a96119b330

Feed Name: Security Ledger

Threat Score
30/100

Date Published: 2013-07-22

Date Updated: 2026-05-08

Author: Paul Roberts

...
...

A security researcher discovered a vulnerability in Facebook’s Developer Application Roles Page that could disclose the primary email addresses of any account—even those with email privacy set to "Only Me." The researcher reported the flaw, Facebook patched it within hours, and awarded a $4,500 bug bounty; exploitation required a Facebook Developer account and basic programming skills.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.