Новости компьютерной безопасности:

  Latest News

Critical Meta Vulnerability Exposed Customer Support Emails, Chats, and Uploaded Files

С сайта: Vulnerability(cybersecuritynews.com)

Critical Meta Vulnerability Exposed Customer Support Emails, Chats, and Uploaded Files

Author: Abinaya

A broken access control flaw in Meta’s shared customer support systems exposed sensitive user data, including emails, chat conversations, and uploaded files.

Discovered during security testing of Meta Horizon Managed Solutions, the vulnerability revealed a broader authorization weakness across multiple support services within Meta’s ecosystem.

What initially seemed to be a limited product-specific flaw quickly escalated into a cross-platform security risk, affecting Meta.com support systems, customer support chats, and internal case management workflows.

At its core, the vulnerability stemmed from inconsistent enforcement of authorization checks in Meta’s backend infrastructure.

Researchers Rony K Roy found that several GraphQL operations returned sensitive support data even when the requesting user lacked the necessary permissions.

This failure allowed unauthorized users to access support cases, internal notes, escalation details, and attachments linked to other users’ support requests.

Meta Vulnerability Exposed
The exposed data included customer support emails exchanged with Meta, chat transcripts with support agents, case metadata, and files uploaded during support interactions.

In many instances, this information contained personally identifiable information, such as names, email addresses, phone numbers, and other contact details voluntarily shared by users during support engagements.

Further analysis by Rony K Roy showed that support case identifiers were assigned sequentially. When combined with the authorization flaw, this enabled attackers to enumerate case IDs and retrieve large volumes of sensitive support records without proper access rights. This significantly increased the potential impact of the vulnerability.

In addition to unauthorized data access, the flaw also allowed certain actions to be carried out without proper permissions. These actions included creating support requests on behalf of other organizations, modifying support case statuses, and adding external users as subscribers to existing cases.

Such capabilities could have allowed attackers to manipulate support workflows or gain visibility into ongoing support interactions.

The affected infrastructure appeared to rely partially on Salesforce-backed systems however, the vulnerability was not directly related to Salesforce itself.

Instead, it stemmed from flaws in how Meta implemented and integrated authorization controls across shared services. The issue aligns with common security classifications, including Broken Access Control (CWE-284), Insecure Direct Object Reference (CWE-639), and Missing Authorization (CWE-862).

According to a Rony K Roy post, the vulnerability was reported in January 2026, upgraded to critical after its broader impact was discovered, and fully remediated by April, with no evidence of active exploitation.

This incident highlights the risks associated with shared backend architectures, where inconsistent authorization logic can affect multiple services.

It also underscores the importance of enforcing strict access controls and validating permissions at every layer of application workflows, especially in systems handling sensitive customer communications.

The Privilege Paths Attackers See That You Don’t: BeyondTrust Pathfinder Platform Does It for You -> Get Free Identity Security Assessment



#Cyber_Security_News #Vulnerability #cyber_security #cyber_security_news

Оригинальная версия на сайте: Critical Meta Vulnerability Exposed Customer Support Emails, Chats, and Uploaded Files
Вернуться к списку новостей К свежим новостям Здесь был google AdSense.
Вместо рекламы товаров началась политическая агитация.
Отключено до получения извинений.

Вернуться к списку новостей Здесь был google AdSense.
Вместо рекламы товаров началась политическая агитация.
Отключено до получения извинений.


Новости проекта CSN:

✉ CSN.net4me.net

Обновление сайта csn.net4me.net

Обновление сайта csn.net4me.net 💻
cyber security news
  • Физически мы переехали на новый сервер. Благодарим наших подписчиков и постоянных читателей за терпение и понимание.
  • Сайт csn.net4me.net полностью адаптирован для работы по шифрованному SSL соединению.
  • Изменен механизм обработки и отображения опасных и критических уязвимостей.

Благодарим что вы с нами.


#CSN_обновление_сайта
https://csn.net4me.net/cyber_security_8301.html

Дополнительный материал

О проекте CSN

Проект CSN.net4me.net родился 16 Марта 2018 года.
Проект находится в самом начале своего развития. Конечно оформление, наполнение будет меняться. Одно останется неизменным - самые свежие новости компьютерной и сетевой безопасности.

О проекте net4me

Проект net4me.net развивался как сборник готовых решений и документации по темам компьютерной безопасности, сетевых решений и СПО (в часности linux). Темпы развития IT отрасли оказались столь быстрыми, что некоторые знания, технологии и информация о них устаревали мгновенно. Тем не менее, некоторый материал net4me.net до сих пор востребован.

Об источниках

Новости берутся CSN из открытых и доступных каждому источников. Авторы проекта стараются подбирать авторитетные и проверенные источники. Но, тем не менее, не несут ответственности за содержимое новостей. В каждой новости указывается источник этой новости, её автор и ссылка на оригинал новости.

Информация

Если вы желаете чтобы новости вашего ресурса были размещены на сайте CSN, то свяжитесь с авторами проекта csn@net4me.net и предложите ссылку на rss или xml ленту новостей вашего ресурса. Любая предложенная информация будет рассмотрена редакцией.