facebook-security

1 article
sort: new top best
clear filter
0 7/10

A clickjacking vulnerability in Instagram's account management endpoint allowed attackers to iframe AJAX responses containing connected application tokens and steal user credentials. The vulnerability existed because the `__a=1` parameter exposed sensitive token data in JSON format without X-Frame-Options protection, despite the regular UI having protections in place.

Instagram Facebook Mohamed A. Baset Mostafa Kassem Seekurity
seekurity.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details