vulns.co
/
GKData.io MCP

IDAuthentication and identity · 2 min read

Facebook SDK message authentication relied on insecure randomness

A USD 66,000 researcher-reported award illustrates how weak message authentication and unsafe rendering can invalidate an SDK trust boundary.

Read the primary source IDAuthentication and identityReviewed 2026-10-02

Root cause

The researcher followed messages from an embedded plugin into SDK handlers and examined their authority checks. A callback identifier was treated as an authentication secret despite coming from non-cryptographic randomness. Separately, a handler interpreted supplied content as active HTML. An origin check alone did not establish that the message content was authorized or safe to render.

Demonstrated impact

The researcher reports script execution and Facebook account takeover under mobile in-app browser conditions. Impact on an arbitrary embedding site depended on its framing controls. The article does not establish that every website using the SDK was affected equally.

Lessons for review

  • Use cryptographic randomness and context binding for values that authorize message handling.
  • Validate the sender, expected message relationship and permitted operation independently of rendering safety.
  • Keep externally supplied content inert and review embedded-browser permissions as a separate trust boundary.
  • Treat these as defensive design recommendations; the source dates a fix but does not establish the precise vendor patch implementation.

Award and evidence

USD 66,000Bug Bounty · Researcher Reported

One researcher-reported bug bounty, not an event total. The article uses $; prior official Meta program reporting supplies USD context. Actual cash settlement is not established.

Re-read the SDK introduction, trust checks, randomness analysis, bounded impact and timeline. Expanded conceptual reasoning without adding reproduction instructions. Original publication remains unknown.

  • Researcher-reported award; no independent vendor confirmation or audited transfer.
  • January 2026 page dates may reflect publication or archive migration; original disclosure is not established.
  • USD normalization uses earlier official program context rather than an award receipt.

Recorded timeline

Reported
2023-06-22explicit
Awarded
2023-06-28explicit
Fixed
2023-12-15explicit · Researcher timeline explicitly labels this as the vendor fix date.

Related visual models

Sources and provenance

  1. Account Takeover in Facebook mobile app due to usage of cryptographically unsecure random number generator and XSS in Facebook JS SDK Youssef Sammouda · reviewed 2026-10-02
  2. Facebook Bug Bounty and BountyCon US-dollar reporting Dan Gurfinkel / Facebook · reviewed 2026-10-02

Record reviewed 2026-10-02. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software