Meta has awarded a $78,000 bounty to researcher Rony K Roy for discovering a vulnerability in its support data system that could have led to the exposure of sensitive customer information. The issue, initially thought minor, was found to allow unauthorized access to support cases and user communications, demonstrating significant flaws in Meta's security framework.
Rony K Roy discovered the vulnerability in January 2026, initially characterizing it as a minor authorization issue in Meta Horizon Managed Solutions.
Upon further analysis, it was revealed that the flaw impacted Meta's backend support infrastructure significantly, risking more sensitive data than anticipated.
The vulnerability involved missing authorization and broken access control, leading to insecure direct object reference (IDOR) issues.
Chaining these vulnerabilities could allow attackers to access Meta support case numbers and communications between users and support personnel.
The flaws could have permitted attackers to view personal user information, support requests, and create or modify support cases without authorization.
This could lead to serious privacy violations and misuse of customer relationships for organizations using Meta Horizon Managed Solutions.
Meta has confirmed that it rolled out patches in April and reported no evidence of exploitation before disclosure of the vulnerability.
Roy has been recognized on Meta's bug bounty leaderboard, affirming the importance of community involvement in security.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Meta has awarded a $78,000 bounty to researcher Rony K Roy for discovering a vulnerability in its support data system that could have led to the exposure of sensitive customer information. The issue, initially thought minor, was found to allow unauthorized access to support cases and user communications, demonstrating significant flaws in Meta's security framework.