September 2018 access token breach
Data compromised
Details not publicly disclosed
Technical writeup
Attackers exploited a vulnerability in the 'View As' feature that allowed them to steal Facebook access tokens. The bug was in the video uploader component that appeared in the context of View As; it incorrectly generated access tokens with the permissions of the user being viewed rather than the viewer. Attackers could then take over accounts.
Root cause
Logic flaw in 'View As' feature when combined with video uploader, leading to token generation with wrong user context.