Root cause
The researcher compared login behavior across an identity-system migration. A previously permitted OAuth return destination began forwarding credentials through a changed redirect flow, losing an earlier containment control. Trust in the initial destination did not establish that the eventual recipient was authorized to receive the credential.
Demonstrated impact
The researcher reports exposure of a privileged first-party credential with account-access implications. Meta confirms possible account takeover requiring user interaction and says its investigation found no abuse. Those statements do not establish that customer accounts were actually compromised.
Lessons for review
- Reassess credential handling and destination trust whenever an identity provider or login flow changes.
- Preserve authorization checks through the full return flow; an initially permitted destination is not a guarantee about later recipients.
- Treat recommendations here as defensive design principles, not a reconstruction of the vendor’s undisclosed patch.
Award and evidence
Vendor-confirmed total attached to one report. Researcher identifies BountyCon and Highest Impact Report bonuses but gives no component allocation; they are not added again. USD uses earlier official program context. Award confirmation does not establish cash settlement.
Matched the researcher, Quest/Oculus OAuth issue and identical report-specific total across the researcher timeline and Meta retrospective. Summarized the migration-related trust failure without reproducing the operational flow.
- Bonus components are not individually quantified; the documented total is counted once.
- The technical article says an associated redirect detail was withheld because it was not fully fixed at publication. No current vulnerability or exact patch implementation is inferred.
- The vendor reports no evidence of abuse; this is not proof that abuse was impossible.
- Cash settlement is unverified; USD denomination uses earlier official program context.
Recorded timeline
- Published
- 2023-01-29explicit · Article date also appears in the researcher’s archive index; historical publication, not the archive’s separate January 2026 entries.
- Public Disclosure
- 2022-12-15explicit · Dated vendor summary precedes the technical article. The page’s December 2024 update explicitly concerns another report.
- Reported
- 2022-08-27explicit
- Awarded
- 2022-09-25explicit · Researcher’s dated total including bonuses; exact funds-transfer date is not established.
- Fixed
- 2022-09-25explicit · Researcher labels this as the Meta fix date. The article withholds details of a separate redirect component that it says was not fully fixed; this is not a claim that every component was remediated that day.
- Award Announced
- 2022-12-15explicit
Sources and provenance
- Account takeover of Facebook/Oculus accounts due to First-Party access_token stealing Youssef Sammouda · reviewed 2026-10-02
- Looking Back at Our Bug Bounty Program in 2022 Neta Oren / Meta · reviewed 2026-10-02
- Facebook Bug Bounty and BountyCon US-dollar reporting Dan Gurfinkel / Facebook · reviewed 2026-10-02
Record reviewed 2026-10-02. Snapshot d5550c789111. Open the complete JSON contract.