Thursday, May 22, 2025
HomeVulnerabilityFacebook Patches Another Vulnerability That Exposed User's Private Information

Facebook Patches Another Vulnerability That Exposed User’s Private Information

Published on

SIEM as a Service

Follow Us on Google News

Facebook patched another vulnerability which allows threat actors to collect private information of facebook user’s.

Imperva Security researcher Ron Masas discovered the bug in Facebook’s Search system while browsing Facebook’s online search results, he noticed that each result contained an iframe element that is used for Facebook internal tracking purpose.

By reading the iframes he found that “most search endpoints, is not cross-site request forgery (CSRF) protected, which normally allows users to share the search results page via a URL.” Masas published a video shows that he could extract the following information by using basic yes or no question.

- Advertisement - Google News

Masas said ZDNet that he could infer if users have liked a particular page, if they’ve taken photos at certain geographical locations, if they had friends of a certain religion in their friends list, if they’ve shared posts with a specific text, if a user has friends with a particular name, if the user has friends living in a specific city or country, and many other highly sensitive details.

To illustrate the attack he created a malicious site which popup or open the Facebook search page, then need to force the user to execute search queries.

He said by manipulating Facebook’s graph search, it’s possible to craft search queries and reflect user behavior. This is especially dangerous for mobile users since the open tab can easily get lost in the background, allowing the attacker to extract the results for multiple queries, while the user is watching a video or reading an article on the attacker’s site.

Masas reported the vulnerability to Facebook responsible disclosure program in May 2018 and the bug was resolved now.

Hackers recently exploted a Zero-Day Flaw in Facebook View As feature to steal 29 Million Accounts Access Tokens that contains information such as security credentials for a login session, user identity, and the permission.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Cityworks Zero-Day Vulnerability Used by UAT-638 Hackers to Infect IIS Servers with Shell Malware

Cisco Talos has uncovered active exploitation of a zero-day remote-code-execution vulnerability, identified as CVE-2025-0994,...

Researchers Warn of ‘Smiao Network’ Cyber Threat Against Taiwan’s Federal Staff

The Foundation for Defense of Democracies (FDD) and cybersecurity firm TeamT5 has exposed an...

Vidar and StealC Malware Delivered Through Viral TikTok Videos by Hackers

A sophisticated social engineering campaign that leverages the viral power of TikTok to distribute...

Halo Security Achieves SOC 2 Type 1 Compliance, Validating Security Controls for Its Attack Surface Management Platform

Halo Security, a leading provider of attack surface management and penetration testing services, today announced it has...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Cityworks Zero-Day Vulnerability Used by UAT-638 Hackers to Infect IIS Servers with Shell Malware

Cisco Talos has uncovered active exploitation of a zero-day remote-code-execution vulnerability, identified as CVE-2025-0994,...

Linux Kernel Zero-Day SMB Vulnerability Discovered via ChatGPT

Security researcher has discovered a zero-day vulnerability (CVE-2025-37899) in the Linux kernel's SMB server...

Cisco Webex Meetings Vulnerability Enables HTTP Response Manipulation

Security researchers have uncovered a vulnerability in Cisco Webex Meetings that could allow remote...