Meta Pays $78,000 Bounty for Customer Support Data Vulnerability
Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data
Discovery and Reward
A security researcher reported receiving a substantial reward from Meta after identifying a critical flaw that exposed sensitive customer support information. The vulnerability was uncovered in January 2026 by independent security professional Rony K Roy, who initially categorized the issue as low-risk. Further investigation revealed the flaw’s broader implications, leading to a significant security update. Meta addressed the issue in April and confirmed no signs of exploitation by malicious actors. Roy disclosed the findings recently and confirmed receiving a $78,000 reward through the company’s bug bounty program. While Meta has not publicly verified the details, Roy’s name appears on the platform’s 2026 top researchers list.
Origin and Technical Details
The flaw originated in Meta Horizon Managed Solutions, an enterprise tool for managing Meta Quest devices and user accounts. Roy’s analysis uncovered a systemic problem within Meta’s backend support systems, involving multiple security gaps. These included insufficient authorization mechanisms, compromised access controls, and insecure direct object reference (IDOR) vulnerabilities.
Impact of the Vulnerability
When combined, these issues could have allowed unauthorized access to support case numbers, user interactions with support teams, and files submitted through support channels. Attackers could also have accessed personal and contact details shared during support sessions. Additionally, the vulnerability might have enabled the creation of fraudulent support requests for organizations using the platform, along with modifications to case statuses and workflows.
Meta’s Response and Patches
Roy’s discovery highlighted the potential for severe data exposure, emphasizing the importance of robust access management in enterprise systems. The researcher’s findings prompted Meta to implement patches, mitigating the risk of exploitation.
Conclusion and Significance
The incident underscores the ongoing challenges of securing complex digital infrastructures and the role of ethical hackers in identifying and addressing critical vulnerabilities before they are exploited.
