Facebook has fixed a bug that could have been abused by someone looking to get their hands on the full names and photos of users.
Atul Agarwal of Secfence Technologies posted information about the issue to the Full Disclosure mailing list 11 August. If someone entered a user’s email address and the wrong password in the login page, the site coughed up the user’s full name and profile picture in addition to an incorrect password message.
The problem could have been exploited for social engineering purposes by phishers, or used to verify random email addresses by checking them against Facebook, Agarwal added.
In a statement, a Facebook spokesperson said the bug has been fixed, and added that the site’s policy prohibits anyone from scraping it for information.
“We have technical systems in place to prevent people’s names and profile photos from showing to unrelated users upon login, but a recently introduced bug temporarily prevented these from working as intended,” according to the spokesperson. “We remedied the situation swiftly.”
Earlier this year, Facebook revamped its privacy controls in response to criticism, and recently moved to extend those controls to users of the mobile version of the site.
Amazon staff in seven cities across US go on strike after company fails to negotiate,…
Two US senators ask president Joe Biden to delay TikTok ban by 90 days after…
Reporters Without Borders calls on Apple to remove AI notification summaries feature after it generates…
North Korea-liked hackers have stolen a record $1.34bn in cryptocurrency so far this year, as…
Suspended prison sentence for Craig Wright for “flagrant breach” of court order, after his false…
Cash-strapped south American country agrees to sell or discontinue its national Bitcoin wallet after signing…