vulns.co
/
GKData.io MCP

AZAuthorization and tenant boundaries · 2 min read

Facebook phone linking lacked account-specific authorization

A 2013 researcher disclosure reports a $20,000 award for unauthorized recovery-phone binding. Its enduring lesson for 2026 applications is that recovery-factor possession and account-change authority require separate checks.

Read the primary source AZAuthorization and tenant boundariesReviewed 2026-10-03

Root cause

Phone possession and requester reauthentication did not establish permission to change the selected account. The missing boundary was authorization over the account receiving a recovery factor.

Demonstrated impact

The researcher describes account takeover without victim interaction, requiring a researcher-controlled account and phone. The demonstrated flow reached password recovery; broader account coverage is the researcher’s claim.

Lessons for review

  • Bind recovery-factor enrollment to the authenticated subject and authorized account.
  • Possession of a new factor cannot substitute for authority over the account it will recover.

Award and evidence

USD 20,000Bug Bounty · Researcher Reported

The researcher states an assigned award, not a settlement. USD is a contextual inference from Facebook’s later official US-dollar program reporting in February 2020, nearly seven years after this disclosure; that source does not independently establish this award’s denomination or payment.

Read the original dated researcher article and its report-specific award statement. Reviewed later official denomination context separately.

  • Exact award and payment dates are unknown; assigned does not establish paid.
  • Currency is inferred from later official program context, not explicit in the individual award statement.
  • Researcher reports the fix added account-specific permission validation; implementation and discovery history are not supplied.

Recorded timeline

Published
2013-06-26explicit
Reported
2013-05-23explicit
Fixed
2013-05-28explicit

Sources and provenance

  1. Hijacking a Facebook Account with SMS Jack Whitton · reviewed 2026-10-03
  2. Facebook 2019 Bug Bounty retrospective, official Spanish edition Dan Gurfinkel / Facebook · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software