vulns.co
/
GKData.io MCP

IDAuthentication and identity · 2 min read

Meta Accounts Center linking lost credential and identity confinement

A researcher-reported USD 30,000 award documents a cross-product account-linking trust failure.

Read the primary source IDAuthentication and identityReviewed 2026-10-03

Root cause

SSO destination validation and browser-message confidentiality did not preserve account-linking credential confinement. Session identity could also differ from the person authorizing the connection, allowing linking authority to cross account boundaries.

Demonstrated impact

The researcher reports unauthorized Facebook linking and persistent account control. Prerequisites included an attacker-controlled Instagram account, account-specific authorization material, an authenticated Facebook user visiting attacker-controlled content, and user confirmation. Mobile sign-in is described as potential; no widespread exploitation is established.

Lessons for review

  • Bind linking approval to both intended account identities, the initiating session, and the exact operation.
  • Constrain credential delivery end to end, including browser-message recipients and final redirect destinations.
  • Make identity changes visible and require fresh authorization when a sensitive linking flow changes account context.
  • Treat these as defensive design recommendations rather than a reconstruction of the undisclosed vendor patch.

Award and evidence

USD 30,000Bug Bounty · Researcher Reported

The article assigns one award to the reported finding. It uses $; USD is inferred from official February 2020 program-wide reporting, roughly five years before this award. That contextual source does not verify the individual denomination or settlement. No conflicting currency was identified.

Read the primary article and dated individual award, checked the researcher archive and official denomination context, and compared report identities with existing Meta records. Retained only conceptual defensive content.

  • The award and overall fix are researcher-reported; vendor confirmation and cash settlement are unverified.
  • Original publication is unknown, so no preferred-window inclusion is claimed.
  • USD relies on earlier program-wide context rather than report-specific currency evidence.
  • The source inconsistently names the final return host; no exact route or operational sequence is inferred.
  • This account-linking report is counted once, not as separate records for its constituent weaknesses.

Recorded timeline

Reported
2024-10-16explicit
Awarded
2024-11-27explicit
Fixed
2024-11-05explicit · Overall researcher timeline label; component-level remediation and patch details are not independently verified.

Sources and provenance

  1. Two-click Facebook account takeover via FXAuth token and blob theft Youssef Sammouda · reviewed 2026-10-03
  2. Una mirada retrospectiva a los aspectos más destacados de Bug Bounty 2019 Dan Gurfinkel / Facebook · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software