Flaw in New Facebook Design Allowed Removal of Profile Photos

A security flaw in the new Facebook design could have been exploited to remove any user’s profile photo.


In late April, at its annual F8 conference, Facebook unveiled FB5, a new design for the social media platform. A group of security researchers was given early access to the new design and one of them, Philippe Harewood, identified an interesting bug.


According to Harewood, a GraphQL call introduced in the new design for the purpose of removing profile pictures from Facebook fan pages could have easily been abused.


“The profile_picture_remove mutator is the name of the GraphQL call for this specific mutation. Normally, the mutation accepts a page identifier in the profile_id field for a Facebook page. Changing the identifier for any user profile allowed a malicious user to dissociate the user’s profile picture,” Harewood explained in a blog post.


It’s worth noting that the attack, for which the researcher has published proof-of-concept (PoC) code, would not actually remove the profile photo from the targeted user’s account and the victim would have been able to easily restore the profile picture.


Nevertheless, Facebook decided to award the white hat hacker a $2,500 bounty.


The company confirmed Harewood’s findings in a blog post published on Monday to announce that Instagram has been added to its Data Abuse Bounty program and the launch of an invitation-only bug bounty program for the Checkout feature in Instagram.


“If this bug was exploited, a person’s profile photo would appear blank. However, the photo would still be sav ..

Support the originator by clicking the read the rest link below.