← All stories
● Covered by 1 source · 1 reportMedium impact

Meta Awards $78,000 Bug Bounty for Critical Customer Support Data Vulnerability

Meta has awarded a $78,000 bounty to researcher Rony K Roy for discovering a vulnerability in its support data system that could have led to the exposure of sensitive customer information. The issue, initially thought minor, was found to allow unauthorized access to support cases and user communications, demonstrating significant flaws in Meta's security framework.

Key points

  • Meta paid $78,000 for a critical vulnerability in customer support data.
  • The bug could have exposed sensitive user information and support case details.
  • Patches were rolled out in April; no exploitation was confirmed.

Discovery of the Vulnerability

Rony K Roy discovered the vulnerability in January 2026, initially characterizing it as a minor authorization issue in Meta Horizon Managed Solutions.

Upon further analysis, it was revealed that the flaw impacted Meta's backend support infrastructure significantly, risking more sensitive data than anticipated.

Details of the Flaw

The vulnerability involved missing authorization and broken access control, leading to insecure direct object reference (IDOR) issues.

Chaining these vulnerabilities could allow attackers to access Meta support case numbers and communications between users and support personnel.

Potential Impact

The flaws could have permitted attackers to view personal user information, support requests, and create or modify support cases without authorization.

This could lead to serious privacy violations and misuse of customer relationships for organizations using Meta Horizon Managed Solutions.

Response and Next Steps

Meta has confirmed that it rolled out patches in April and reported no evidence of exploitation before disclosure of the vulnerability.

Roy has been recognized on Meta's bug bounty leaderboard, affirming the importance of community involvement in security.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~39 min · 34 stories · Jul 21

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Meta has awarded a $78,000 bounty to researcher Rony K Roy for discovering a vulnerability in its support data system that could have led to the exposure of sensitive customer information. The issue, initially thought minor, was found to allow unauthorized access to support cases and user communications, demonstrating significant flaws in Meta's security framework.