
Critical Meta IDOR Flaw Let Attackers Access Customer Support Cases
A critical broken access control vulnerability in Meta’s customer support infrastructure allowed attackers to read private support emails, chats, and case data belonging to other users, and even manipulate support workflows on their behalf. Independent researcher Rony K Roy discovered the flaw, which Meta patched by April 2026 after awarding a 78,000 USD bounty for […]
The post Critical Meta IDOR Flaw Let Attackers Access Customer Support Cases appeared first on Cyber Security News.