Root cause
Insufficient verification-attempt limits undermined phone ownership checks, while linked-account state changes could affect an existing SMS authentication factor.
Demonstrated impact
The vendor confirms possible SMS-based two-factor authentication bypass. The researcher demonstrated factor revocation; this alone does not establish password disclosure or an authenticated session.
Lessons for review
- Enforce verification-attempt limits consistently across linked applications.
- Require verified ownership before changing another account’s recovery or second-factor state.
Award and evidence
Vendor total for one report. Researcher describes an initial September award and a December adjustment; component amounts are unknown and are not added on top. USD is contextualized by earlier official program reporting; settlement is unverified.
Matched the researcher’s explicit vendor-retrospective link, name and account-verification issue to Meta’s per-report award. Retained final reward adjustment separately from cash settlement and fix confirmation.
- Exact reward-component amounts and cash-transfer date are unknown.
- Fix-confirmation date does not prove an exact deployment date.
- USD notation uses earlier official program context.
Recorded timeline
- Published
- 2023-01-20explicit · Primary technical article date; distinct from the earlier vendor summary.
- Public Disclosure
- 2022-12-15explicit · Vendor’s high-level public summary. Researcher confirms this same-day highlight; a 2024 update concerns another case.
- Reported
- 2022-09-14explicit
- Awarded
- 2022-12-15explicit · Final additional award; initial amount was awarded September 24, 2022.
- Award Announced
- 2022-12-15explicit
Sources and provenance
- Two Factor Authentication Bypass On Facebook Gtm Mänôz · reviewed 2026-10-02
- Looking Back at Our Bug Bounty Program in 2022 Neta Oren / Meta · reviewed 2026-10-02
- Facebook Bug Bounty and BountyCon US-dollar reporting Dan Gurfinkel / Facebook · reviewed 2026-10-02
Record reviewed 2026-10-02. Snapshot 53796974ace8. Open the complete JSON contract.