vulns.co
/
GKData.io MCP

AZAuthorization and tenant boundaries · 2 min read

Meta Pixel cross-window handling lost message and token authority

The USD 32,500 researcher-reported award illustrates the distinction between message origin and disclosure authority.

Read the primary source AZAuthorization and tenant boundariesReviewed 2026-10-02

Root cause

The researcher followed how browser messages influenced requests containing page context. A trusted-origin check substituted for a complete authorization decision: the requested operation and recipient identity were not bound to the protected context. The failure allowed sensitive information to cross into a different identity’s request context.

Demonstrated impact

The researcher reports authorization-material exposure and consequent Instagram takeover with user interaction. Wider script deployment does not establish equivalent impact on every embedding site or evidence of real-world abuse.

Lessons for review

  • Check the expected sender relationship and message structure, then independently authorize the requested operation and recipient.
  • Define a minimal disclosure contract for analytics and integration messages; omit authentication artifacts from general page context.
  • Review grant-to-client binding separately from message transport and preserve those distinctions in evidence.
  • These are defensive recommendations; the precise vendor patch and the separately alleged grant-binding fix are not independently verified.

Award and evidence

USD 32,500Bug Bounty · Researcher Reported

One researcher-reported bug bounty, not an event total. The article uses $; prior official Meta program reporting supplies USD context. Actual cash settlement is not established.

Reviewed the primary explanation and timeline; clarified component-level uncertainty while preserving unknown original publication.

  • Researcher-reported award; no independent vendor confirmation or audited transfer.
  • January 2026 page dates may reflect publication or archive migration; original disclosure is not established.
  • USD normalization uses earlier official program context rather than an award receipt.
  • A separate grant-binding flaw is alleged and described as disputed; vendor confirmation and its precise fix date are unverified.

Recorded timeline

Reported
2024-10-16explicit
Awarded
2025-02-12explicit
Fixed
2024-10-24explicit · Overall fix date in the researcher timeline. A separately alleged, disputed grant-binding component has no confirmed fix date; this timestamp does not cover it.

Related visual models

Sources and provenance

  1. Instagram account takeover via Meta Pixel script abuse Youssef Sammouda · reviewed 2026-10-02
  2. Facebook Bug Bounty and BountyCon US-dollar reporting Dan Gurfinkel / Facebook · reviewed 2026-10-02

Record reviewed 2026-10-02. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software