Root cause
Phone possession and requester reauthentication did not establish permission to change the selected account. The missing boundary was authorization over the account receiving a recovery factor.
Demonstrated impact
The researcher describes account takeover without victim interaction, requiring a researcher-controlled account and phone. The demonstrated flow reached password recovery; broader account coverage is the researcher’s claim.
Lessons for review
- Bind recovery-factor enrollment to the authenticated subject and authorized account.
- Possession of a new factor cannot substitute for authority over the account it will recover.
Award and evidence
The researcher states an assigned award, not a settlement. USD is a contextual inference from Facebook’s later official US-dollar program reporting in February 2020, nearly seven years after this disclosure; that source does not independently establish this award’s denomination or payment.
Read the original dated researcher article and its report-specific award statement. Reviewed later official denomination context separately.
- Exact award and payment dates are unknown; assigned does not establish paid.
- Currency is inferred from later official program context, not explicit in the individual award statement.
- Researcher reports the fix added account-specific permission validation; implementation and discovery history are not supplied.
Recorded timeline
- Published
- 2013-06-26explicit
- Reported
- 2013-05-23explicit
- Fixed
- 2013-05-28explicit
Sources and provenance
- Hijacking a Facebook Account with SMS Jack Whitton · reviewed 2026-10-03
- Facebook 2019 Bug Bounty retrospective, official Spanish edition Dan Gurfinkel / Facebook · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.