Root cause
The researcher followed messages from an embedded plugin into SDK handlers and examined their authority checks. A callback identifier was treated as an authentication secret despite coming from non-cryptographic randomness. Separately, a handler interpreted supplied content as active HTML. An origin check alone did not establish that the message content was authorized or safe to render.
Demonstrated impact
The researcher reports script execution and Facebook account takeover under mobile in-app browser conditions. Impact on an arbitrary embedding site depended on its framing controls. The article does not establish that every website using the SDK was affected equally.
Lessons for review
- Use cryptographic randomness and context binding for values that authorize message handling.
- Validate the sender, expected message relationship and permitted operation independently of rendering safety.
- Keep externally supplied content inert and review embedded-browser permissions as a separate trust boundary.
- Treat these as defensive design recommendations; the source dates a fix but does not establish the precise vendor patch implementation.
Award and evidence
One researcher-reported bug bounty, not an event total. The article uses $; prior official Meta program reporting supplies USD context. Actual cash settlement is not established.
Re-read the SDK introduction, trust checks, randomness analysis, bounded impact and timeline. Expanded conceptual reasoning without adding reproduction instructions. Original publication remains unknown.
- Researcher-reported award; no independent vendor confirmation or audited transfer.
- January 2026 page dates may reflect publication or archive migration; original disclosure is not established.
- USD normalization uses earlier official program context rather than an award receipt.
Recorded timeline
- Reported
- 2023-06-22explicit
- Awarded
- 2023-06-28explicit
- Fixed
- 2023-12-15explicit · Researcher timeline explicitly labels this as the vendor fix date.
Sources and provenance
- Account Takeover in Facebook mobile app due to usage of cryptographically unsecure random number generator and XSS in Facebook JS SDK Youssef Sammouda · reviewed 2026-10-02
- Facebook Bug Bounty and BountyCon US-dollar reporting Dan Gurfinkel / Facebook · reviewed 2026-10-02
Record reviewed 2026-10-02. Snapshot d5550c789111. Open the complete JSON contract.