Facebook bug gave developers access to private photos of 6.8 million users
Full article553 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Facebook says the bug existed for 12 days and was fixed promptly after discovery on Sept. 25.
Facebook said Friday that a bug on its platform exposed 6.8 million users’ private photos to developers for 12 days in September.
The flaw was in Facebook’s photo API, the company said, and accidentally gave developers access to private photos. The API should only allow authorized applications to access public photos on users’ timelines.
“In this case, the bug potentially gave developers access to other photos, such as those shared on Marketplace or Facebook Stories. The bug also impacted photos that people uploaded to Facebook but chose not to post,” Facebook engineering director Tomer Bar said in a blog post. “We’re sorry this happened.”
The bug seems to have impacted 1,500 apps made by 876 developers, according to the blog post. Bar said Facebook will be rolling out a feature for app developers to see which of their users were affected by the bug and “will be working with those developers to delete the photos from impacted users.”
For now, users can check whether or not their photos were exposed on a Facebook help page here.
Bar said it existed from Sept. 13 to Sept. 25. Facebook discovered and remedied the bug on Sept. 25, TechCrunch reported.
It’s not clear why Facebook took nearly two months to disclose the photo API bug. It’s worth noting that Sept. 25 is also the date the company discovered a vulnerability that gave hackers access to 30 million users’ login tokens — a much more serious security flaw. Facebook disclosed that bug within days.
The social media giant has been under fire over the past several months because of the way it manages user data. Much of the recent criticism started with the Cambridge Analytica ordeal, which showed that developers were abusing access to users’ data through APIs for political purposes.
Facebook did not say whether the bug disclosed Friday was abused by developers. It’s not clear whether developers even knew they had access to more than what they were supposed to.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/facebook-photo-api-bug-december-2018/