vulns.co
/
GKData.io MCP

IDAuthentication and identity · 2 min read

Meta account verification weakened linked SMS authentication state

Meta confirms a USD 27,200 total award for this account-verification report.

Read the primary source IDAuthentication and identityReviewed 2026-10-02

Root cause

Insufficient verification-attempt limits undermined phone ownership checks, while linked-account state changes could affect an existing SMS authentication factor.

Demonstrated impact

The vendor confirms possible SMS-based two-factor authentication bypass. The researcher demonstrated factor revocation; this alone does not establish password disclosure or an authenticated session.

Lessons for review

  • Enforce verification-attempt limits consistently across linked applications.
  • Require verified ownership before changing another account’s recovery or second-factor state.

Award and evidence

USD 27,200Bug Bounty · Vendor Confirmed

Vendor total for one report. Researcher describes an initial September award and a December adjustment; component amounts are unknown and are not added on top. USD is contextualized by earlier official program reporting; settlement is unverified.

Matched the researcher’s explicit vendor-retrospective link, name and account-verification issue to Meta’s per-report award. Retained final reward adjustment separately from cash settlement and fix confirmation.

  • Exact reward-component amounts and cash-transfer date are unknown.
  • Fix-confirmation date does not prove an exact deployment date.
  • USD notation uses earlier official program context.

Recorded timeline

Published
2023-01-20explicit · Primary technical article date; distinct from the earlier vendor summary.
Public Disclosure
2022-12-15explicit · Vendor’s high-level public summary. Researcher confirms this same-day highlight; a 2024 update concerns another case.
Reported
2022-09-14explicit
Awarded
2022-12-15explicit · Final additional award; initial amount was awarded September 24, 2022.
Award Announced
2022-12-15explicit

Sources and provenance

  1. Two Factor Authentication Bypass On Facebook Gtm Mänôz · reviewed 2026-10-02
  2. Looking Back at Our Bug Bounty Program in 2022 Neta Oren / Meta · reviewed 2026-10-02
  3. Facebook Bug Bounty and BountyCon US-dollar reporting Dan Gurfinkel / Facebook · reviewed 2026-10-02

Record reviewed 2026-10-02. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software