Root cause
A browser message origin became trusted script-host configuration without origin authorization.
Demonstrated impact
The researcher reports script execution and describes possible account takeover. The scenario depends on specific embedded-browser, initialization and content-policy conditions plus influence over permitted third-party content. Account impact additionally assumes user interaction and an authenticated session; universal or interaction-free exploitation is not established.
Lessons for review
- Authorize message origins and senders independently of message content; treat an integration identifier as data rather than proof of authority.
- Keep script-source authority separate from mutable messaging configuration, and review it together with browser isolation and content policy.
- Define regression coverage for initialization state, embedded-browser behavior and third-party trust; distinguish observed execution from modeled account impact.
Award and evidence
Separate from Bug #2; no aggregation. The dollar sign is interpreted as USD using official 2020 program context, nearly five years earlier. This does not establish individual settlement currency or payment.
Freshly read the primary article and official denomination context; compared report boundaries against the existing backend record. No live testing.
- Researcher-reported award, not vendor-confirmed payment; settlement date remains unknown.
- USD is contextual inference with an almost five-year gap, not an individual receipt.
- Original publication and earliest disclosure remain unknown.
- The narrative puts Bug #2 after reporting Bug #1; the labeled timeline orders reports oppositely. Dates follow labels without reconciling the conflict.
- Execution is researcher-reported; completed account takeover, population-wide exposure and exact patch coverage are not independently established.
- The article-wide zero-click framing should not be generalized to this interaction-dependent finding.
Recorded timeline
- Reported
- 2024-11-24explicit · Explicit Timeline entry labeled Bug #1.
- Awarded
- 2024-12-24explicit · Explicit Timeline entry labeled Bug #1.
- Fixed
- 2024-12-11explicit · Explicit Timeline entry labeled Bug #1.
Sources and provenance
- Multiple XSS in Meta Conversion API Gateway Leading to Zero-Click Account Takeover Youssef Sammouda · reviewed 2026-10-03
- Facebook Bug Bounty and BountyCon US-dollar reporting Dan Gurfinkel / Facebook · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.