A researcher received $78,000 for a bug in Meta's

✨ Megiddo

✨ President ✨
Staff member
976
263
Independent security researcher Rony K. Roy earned $78,000 for discovering a vulnerability in the internal infrastructure of Meta's support team (the company's activities are considered extremist and are banned in Russia). The expert explained that the bug he discovered could have led to the disclosure of user correspondence with the support team, uploaded files, and personal data.

In his blog, Roy writes that he discovered the problem and reported it to the developers back in January 2026. Initially, the researcher believed he had found a minor bug in the authorization mechanism of Meta Horizon Managed Solutions, a corporate platform for centralized administration of Meta Quest devices.

However, further analysis revealed that the problem was much more serious and affected Meta's overall backend support infrastructure. According to Roy, in April, the company's specialists released patches and reported no evidence of attackers exploiting the vulnerability.

The bug was based on a combination of several access control issues, including missing permissions checks and IDOR (Insecure Direct Object Reference). By chaining these bugs together, an attacker could brute-force support ticket numbers and access related tickets.

This compromised email and chat conversations between users and support staff, ticket details, attached files, and personal and contact information shared with Meta specialists.

Roy emphasizes that the potential attack wasn't limited to reading other people's data. The bug also allowed for the creation of tickets on behalf of organizations using Meta Horizon Managed Solutions, modification of ticket processing processes, editing of ticket statuses, and adding third-party subscribers to tickets.

It's worth noting that Meta representatives have neither confirmed a fix for the vulnerability nor the $78,000 payment to the researcher. However, Roy does hold a high position in the ranking of Meta's 2026 bug bounty program participants. @xakep.ru