Meta account recovery feature is reported to have a critical design flaw that could directly expose users' sensitive information

robot
Abstract generation in progress
Golden Finance reports that on June 8th, GoPlus posted on the X platform stating that the Meta account recovery feature has been exposed to a high-risk design flaw, which directly leaks users' phone numbers, emails, and PII (personally identifiable information). Attackers only need to input the META username, without any login or verification, to directly access the user's linked email, phone number, and other complete PII, which could pose significant risks to users, such as: large-scale phishing attacks, SIM swapping attacks, account takeover and identity theft, targeted social engineering attacks. Recommendations: remove or replace leaked email/phone number used for recovery; change related account passwords and enable 2FA; do not click any emails or messages related to "Account Anomaly," "Verification," or "Password Reset"; set up multi-channel verification, which can be verified through official documentation or other official social media channels.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments