CyberSecurity

A $78,000 Catch: How a Researcher Exposed Meta’s Customer Support Data Hole

Published

on

Inside the Vulnerability That Cost Meta $78,000

Meta has paid out a $78,000 bug bounty to a security researcher who uncovered a serious flaw in the company’s customer support infrastructure. The vulnerability, which went deeper than it first appeared, could have let attackers snoop on private conversations between users and Meta support teams.

Independent researcher Rony K Roy reported the issue in January 2026. At first glance, it looked like a minor authorization glitch. But Roy kept digging. What he found was a chain of security failures that exposed far more than he initially expected.

Meta patched the flaw in April. The company says it found no evidence that anyone had exploited it maliciously. Still, the payout — one of the larger bounties in recent memory — underscores just how dangerous the hole could have been.

From Horizon to Backend: How the Flaw Escalated

Roy initially spotted the problem in Meta Horizon Managed Solutions, an enterprise platform for managing Meta Quest devices and user accounts. That alone might have been a contained issue. But the researcher soon realized the same broken access control ran through Meta’s broader support backend.

The core problem: missing authorization checks, broken access controls, and an insecure direct object reference (IDOR) vulnerability. Chained together, these weaknesses allowed an attacker to enumerate Meta support case numbers and pull up entire support tickets.

Think about what that means. Anyone exploiting this could read email and chat exchanges between customers and Meta support. They could view case details, download files submitted through support requests, and scrape personal and contact information that users had voluntarily shared with Meta.

What an Attacker Could Have Done

The risks didn’t stop at data theft. Roy’s analysis showed that an attacker could also:

  • Create support requests on behalf of organizations using Meta Horizon Managed Solutions
  • Modify support workflows, including changing case statuses
  • Add unauthorized subscribers to support cases

Imagine a bad actor hijacking a company’s open support ticket with Meta, altering its priority, or injecting themselves into the conversation. For enterprise customers managing fleets of Quest devices, that’s not just a privacy breach — it’s a operational security nightmare.

Roy disclosed his findings publicly last week. He told SecurityWeek that Meta had confirmed the vulnerability and paid the $78,000 bounty. Meta has not responded to requests for comment, but Roy appears on the company’s 2026 bug bounty leaderboard as one of its top researchers.

Broken Access Control: A Recurring Theme

This isn’t an exotic vulnerability. Broken access control and IDOR flaws are among the most common — and most dangerous — issues in web applications. The OWASP Top 10 has ranked broken access control as the number-one security risk for years.

What made this case notable was the scope. A seemingly minor authorization bug in a niche enterprise product turned out to be a gateway into Meta’s core support systems. It’s a reminder that security researchers often need to pull on loose threads to find the real damage.

Roy’s approach — reporting a limited-severity issue, then expanding the analysis — is exactly the kind of persistence that bug bounty programs are designed to reward. Meta’s $78,000 payout reflects that.

What This Means for Meta Users

For ordinary Facebook, Instagram, and WhatsApp users, the immediate risk is low. Meta says it patched the vulnerability before any known exploitation. But the incident raises legitimate questions about how much data Meta’s support systems hold, and how well it’s protected.

When you contact Meta support — whether about a hacked account, a billing issue, or a content takedown — you’re sharing details you probably wouldn’t post publicly. That trust is the foundation of customer support. A vulnerability like this breaks it.

Meta’s bug bounty program has long been one of the most generous in the tech industry. The company paid out over $2 million in bounties in 2025 alone. But programs like this are only as good as the researchers who find the flaws — and the company’s willingness to fix them quickly.

In this case, Meta did both. The patch came within three months of the initial report. No evidence of exploitation. A substantial bounty paid. That’s the ideal outcome.

Still, the vulnerability’s existence highlights a persistent challenge for large platforms: their attack surface is enormous. A single broken access control check in a backend API can expose millions of support records. Finding and fixing those gaps before attackers do is a never-ending race.

Roy’s $78,000 check is proof that the race is worth running.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version