logo

Facebook bug could have allowed attacker to take over accounts

ID: 3751c65d-54dc-5674-ac60-3d389908b564

STIX ID: report--3751c65d-54dc-5674-ac60-3d389908b564

Feed Name: Malwarebytes Blog

Threat Score
55/100

Date Published: 2024-02-29

Date Updated: 2026-04-28

...
...

A vulnerability in Facebook's 'Send code via Facebook notification' password reset flow allowed attackers to brute-force 6-digit reset codes that remained valid and unchanged for two hours; a correct guess returned a 302 redirect enabling password reset and account takeover, potentially without any interaction from the victim in certain notification flows. The flaw was reported by a bounty hunter (Samip Aryal), has been patched by Facebook, and users are advised to enable 2FA and monitor reset notifications.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.