Facebook bug could have allowed attacker to take over accounts
ID: 3751c65d-54dc-5674-ac60-3d389908b564
STIX ID: report--3751c65d-54dc-5674-ac60-3d389908b564
Feed Name: Malwarebytes Blog
A vulnerability in Facebook's 'Send code via Facebook notification' password reset flow allowed attackers to brute-force 6-digit reset codes that remained valid and unchanged for two hours; a correct guess returned a 302 redirect enabling password reset and account takeover, potentially without any interaction from the victim in certain notification flows. The flaw was reported by a bounty hunter (Samip Aryal), has been patched by Facebook, and users are advised to enable 2FA and monitor reset notifications.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
