Root cause
Server-delivered interface configuration exposed an application credential to a client. The researcher distinguished application-level authority from ordinary client-token authority, identifying a mismatch between the data needed for rendering and the privilege carried by an embedded credential.
Demonstrated impact
The researcher reports retrieving application-role metadata. Meta confirms credential exposure but says independent protections limited further impact and it found no evidence of abuse. Unrestricted administration, account takeover and actual customer compromise were not established.
Lessons for review
- Classify every credential by its authority and intended holder before deciding whether it belongs in client-visible data.
- Keep privileged application credentials inside controlled server contexts; minimize the capabilities available to client integrations.
- Preserve independent authorization checks after credential validation, and distinguish the demonstrated exposure from hypothetical downstream consequences.
- Treat containment and least-privilege recommendations as design guidance; the sources do not document the complete vendor patch.
Award and evidence
Records the vendor-confirmed base once. The researcher separately lists $6,000 league, $2,250 delay and $50 event bonuses; these are not added to this amount or counted as separate findings. USD uses earlier official program denomination context; settlement is unknown.
Matched Meta’s named researcher and report-specific award to its directly linked technical article. Separated credential exposure, observed metadata access and vendor-stated containment.
- The vendor confirms the base; bonus breakdown and report/award timeline are researcher-reported.
- Original researcher publication and exact fix deployment are uncertain; the vendor bulletin supplies the publication date used here.
- The currency reference is older program context, not a report-specific settlement record.
- No full patch implementation or unrestricted downstream compromise is established.
Recorded timeline
- Published
- 2022-07-20explicit · Dated vendor publication is used. The researcher page presents February 24, 2022 and August 27, 2024 without a clearly extracted original-versus-update label; its original public release remains uncertain.
- Public Disclosure
- 2022-07-20explicit · Vendor discussion and direct researcher link establish public availability by this date, not the earliest possible disclosure.
- Reported
- 2022-02-24explicit
- Awarded
- 2022-05-19explicit
- Award Announced
- 2022-07-20explicit · Public vendor confirmation; an earlier researcher announcement is possible.
Sources and provenance
- How Meta and the security industry collaborate to secure the internet Meta Engineering · reviewed 2026-10-02
- Instagram App Access Token Philippe Harewood · reviewed 2026-10-02
- Facebook Bug Bounty and BountyCon US-dollar reporting Dan Gurfinkel / Facebook · reviewed 2026-10-02
Record reviewed 2026-10-02. Snapshot 53796974ace8. Open the complete JSON contract.