Facebook Uncovers 'Security Issue' Affecting Nearly 50 Million Accounts

Facebook this morning announced that its engineering team on Tuesday discovered that hackers have exploited a vulnerability in its code, allowing hackers to steal Facebook access tokens for almost 50 million accounts.

According to Facebook, hackers took advantage of security flaws in its "View As" code, which is a feature designed to let people see what their profile looks like to someone else. The Facebook access tokens that were stolen are digital keys that allow people to stay logged in to Facebook.

facebooksecurity

This attack exploited the complex interaction of multiple issues in our code. It stemmed from a change we made to our video uploading feature in July 2017, which impacted "View As." The attackers not only needed to find this vulnerability and use it to get an access token, they then had to pivot from that account to others to steal more tokens.

It is not clear whether the accounts affected were misused or have had information accessed at this time, and Facebook does not know who executed the attacks.

Facebook says that the vulnerability has been patched at this time, and authorities have been informed. Facebook has reset the access tokens of the nearly 50 million accounts that were affected along with another 40 million accounts that have been subject to a "View As" lookup in the last year.

Customers who have been logged out of their apps will receive a message about what happened once they log back in.

While a security review is conducted, Facebook is turning off the "View As" feature that was used for the hack.

Facebook says that it is "sorry this happened" and that people's privacy and security "is incredibly important." No one needs to change their passwords, according to Facebook, but those concerned can visit the "Security and Login" section in settings to log out of all devices at once.

Today's Facebook hack comes just a day after Facebook was found to be using phone numbers that customers provided for 2-factor authentication for ad targeting purposes and shadow contact building.

Top Rated Comments

snowboarder Avatar
65 months ago
Facebook is the worst thing ever. It destroyed the society and made people dumb.
Score: 25 Votes (Like | Disagree)
iapplelove Avatar
65 months ago
Never had a FB account.
Score: 22 Votes (Like | Disagree)
oneMadRssn Avatar
65 months ago
Stop using Facebook people! There is a better and safer alternative to each fb feature. I can't think of a single good reason to still be on Facebook - there are none.
Score: 22 Votes (Like | Disagree)
Jimmy Bubbles Avatar
65 months ago
even more of a reason to delete your Facebook...Get on Gab!
Score: 21 Votes (Like | Disagree)
oneMadRssn Avatar
65 months ago
1) My work group is on FB chat. Gonna be a pain to suggest a different one.
2) Dank memes.
1. get a better job.

2. all the good memes are on reddit first.
Score: 13 Votes (Like | Disagree)
cmaier Avatar
65 months ago
what an awful company.
Score: 12 Votes (Like | Disagree)

Popular Stories

iOS 17

Apple Releases iOS 17.0.1 and iPadOS 17.0.1 With Bug Fixes, Plus iOS 17.0.2 for iPhone 15 Models

Thursday September 21, 2023 10:28 am PDT by
Apple today released iOS 17.0.1 and iPadOS 17.0.1 updates for the iPhone and the iPad, adding bug fixes to the new software. The iOS 17.0.1 and iPadOS 17.0.1 updates come just a few days after Apple launched iOS 17 and iPadOS 17. The software, which is build 21A340, can be downloaded on eligible iPhones and iPads over-the-air by going to Settings > General > Software Update. There is a...
iPhone 15 Pro Lineup Feature

iPhone 15 Models Feature New Setting to Strictly Prevent Charging Beyond 80%

Tuesday September 19, 2023 2:04 pm PDT by
All of the iPhone 15 and iPhone 15 Pro models feature a new battery health setting that prevents the devices from charging beyond 80% at all times when enabled, as confirmed by The Verge's Allison Johnson during a Q&A session today. The new setting is separate from the pre-existing Optimized Battery Charging feature on iPhones, which intelligently delays charging past 80% until a more...
emojipedia 15 1 emoji

Emoji Coming to Future iOS 17 Update Include Shaking Head, Brown Mushroom, Lime, Phoenix and More

Tuesday September 19, 2023 12:43 pm PDT by
As Apple was announcing new iPhone models last week, the Unicode Consortium was officially approving new emoji characters that are set to be added to smartphones starting in 2024. Mockup of new emoji from Emojipedia Approved Unicode 15.1 emoji include phoenix, lime, an edible mushroom, shaking head vertically (as in a "yes" nod), shaking head horizontally (a "no" head shake), and broken...
iPhone 15 Pro Max 5x Optical Zoom Limit Feature 1

Apple Explains Why iPhone 15 Pro Max is Limited to 5x Optical Zoom

Wednesday September 20, 2023 9:52 am PDT by
In an interview with Numerama's Nicolas Lellouche, Apple's VP of camera software engineering Jon McCormack explained why the iPhone 15 Pro Max's tetraprism lens system is limited to 5x optical zoom, instead of 10x like on Samsung's Galaxy S23 Ultra. The interview is in French, so quotes below are computer translated. Apple says the Telephoto lens on the iPhone 15 Pro Max features the...