← Facebook

September 2018 access token breach

2018 50.0M records affected Share on X

Data compromised

Details not publicly disclosed

Technical writeup

Attackers exploited a vulnerability in the 'View As' feature that allowed them to steal Facebook access tokens. The bug was in the video uploader component that appeared in the context of View As; it incorrectly generated access tokens with the permissions of the user being viewed rather than the viewer. Attackers could then take over accounts.

Root cause

Logic flaw in 'View As' feature when combined with video uploader, leading to token generation with wrong user context.

References