www.securityweek.com 7/21/2026, 10:50:40 AM · external

Researcher pockets $78k Meta bounty for support data flaw

Researcher pockets $78k Meta bounty for support data flaw
CyberSIXT Evidence Panel Source marked as original reporting

A security researcher, Rony K Roy, received a $78,000 bug bounty from Meta after uncovering a critical vulnerability that exposed customer support data while initially reporting a less severe authorization issue in January 2026. The flaw, which was more widespread than expected, involved missing authorization and broken access control that allowed attackers to potentially access confidential support communications and manipulate support requests on the Meta platform. Patches were rolled out by Meta in April 2026, and no evidence of exploitation was found.

View full article

Article by CyberSIXT