Saturday, February 8, 2025
HomeVulnerabilityFacebook Patches Another Vulnerability That Exposed User's Private Information

Facebook Patches Another Vulnerability That Exposed User’s Private Information

Published on

SIEM as a Service

Follow Us on Google News

Facebook patched another vulnerability which allows threat actors to collect private information of facebook user’s.

Imperva Security researcher Ron Masas discovered the bug in Facebook’s Search system while browsing Facebook’s online search results, he noticed that each result contained an iframe element that is used for Facebook internal tracking purpose.

By reading the iframes he found that “most search endpoints, is not cross-site request forgery (CSRF) protected, which normally allows users to share the search results page via a URL.” Masas published a video shows that he could extract the following information by using basic yes or no question.

Masas said ZDNet that he could infer if users have liked a particular page, if they’ve taken photos at certain geographical locations, if they had friends of a certain religion in their friends list, if they’ve shared posts with a specific text, if a user has friends with a particular name, if the user has friends living in a specific city or country, and many other highly sensitive details.

To illustrate the attack he created a malicious site which popup or open the Facebook search page, then need to force the user to execute search queries.

He said by manipulating Facebook’s graph search, it’s possible to craft search queries and reflect user behavior. This is especially dangerous for mobile users since the open tab can easily get lost in the background, allowing the attacker to extract the results for multiple queries, while the user is watching a video or reading an article on the attacker’s site.

Masas reported the vulnerability to Facebook responsible disclosure program in May 2018 and the bug was resolved now.

Hackers recently exploted a Zero-Day Flaw in Facebook View As feature to steal 29 Million Accounts Access Tokens that contains information such as security credentials for a login session, user identity, and the permission.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Autonomous LLMs Reshaping Pen Testing: Real-World AD Breaches and the Future of Cybersecurity

Large Language Models (LLMs) are transforming penetration testing (pen testing), leveraging their advanced reasoning...

Securing GAI-Driven Semantic Communications: A Novel Defense Against Backdoor Attacks

Semantic communication systems, powered by Generative AI (GAI), are transforming the way information is...

Cybercriminals Target IIS Servers to Spread BadIIS Malware

A recent wave of cyberattacks has revealed the exploitation of Microsoft Internet Information Services...

Hackers Leveraging Image & Video Attachments to Deliver Malware

Cybercriminals are increasingly exploiting image and video files to deliver malware, leveraging advanced techniques...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Microsoft Sysinternals 0-Day Vulnerability Enables DLL Injection Attacks on Windows

A critical zero-day vulnerability has been discovered in Microsoft Sysinternals tools, posing a serious security threat...

7-Zip 0-Day Flaw Added to CISA’s List of Actively Exploited Vulnerabilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical 0-day vulnerability...

Logsign Vulnerability Allows Remote Attackers to Bypass Authentication

A critical security vulnerability has been identified and disclosed in the Logsign Unified SecOps...