Facebook Uncovers 'Security Issue' Affecting Nearly 50 Million Accounts

Facebook this morning announced that its engineering team on Tuesday discovered that hackers have exploited a vulnerability in its code, allowing hackers to steal Facebook access tokens for almost 50 million accounts.

According to Facebook, hackers took advantage of security flaws in its "View As" code, which is a feature designed to let people see what their profile looks like to someone else. The Facebook access tokens that were stolen are digital keys that allow people to stay logged in to Facebook.

facebooksecurity

This attack exploited the complex interaction of multiple issues in our code. It stemmed from a change we made to our video uploading feature in July 2017, which impacted "View As." The attackers not only needed to find this vulnerability and use it to get an access token, they then had to pivot from that account to others to steal more tokens.

It is not clear whether the accounts affected were misused or have had information accessed at this time, and Facebook does not know who executed the attacks.

Facebook says that the vulnerability has been patched at this time, and authorities have been informed. Facebook has reset the access tokens of the nearly 50 million accounts that were affected along with another 40 million accounts that have been subject to a "View As" lookup in the last year.

Customers who have been logged out of their apps will receive a message about what happened once they log back in.

While a security review is conducted, Facebook is turning off the "View As" feature that was used for the hack.

Facebook says that it is "sorry this happened" and that people's privacy and security "is incredibly important." No one needs to change their passwords, according to Facebook, but those concerned can visit the "Security and Login" section in settings to log out of all devices at once.

Today's Facebook hack comes just a day after Facebook was found to be using phone numbers that customers provided for 2-factor authentication for ad targeting purposes and shadow contact building.

Top Rated Comments

snowboarder Avatar
73 months ago
Facebook is the worst thing ever. It destroyed the society and made people dumb.
Score: 25 Votes (Like | Disagree)
iapplelove Avatar
73 months ago
Never had a FB account.
Score: 22 Votes (Like | Disagree)
oneMadRssn Avatar
73 months ago
Stop using Facebook people! There is a better and safer alternative to each fb feature. I can't think of a single good reason to still be on Facebook - there are none.
Score: 22 Votes (Like | Disagree)
Jimmy Bubbles Avatar
73 months ago
even more of a reason to delete your Facebook...Get on Gab!
Score: 21 Votes (Like | Disagree)
oneMadRssn Avatar
73 months ago
1) My work group is on FB chat. Gonna be a pain to suggest a different one.
2) Dank memes.
1. get a better job.

2. all the good memes are on reddit first.
Score: 13 Votes (Like | Disagree)
cmaier Avatar
73 months ago
what an awful company.
Score: 12 Votes (Like | Disagree)

Popular Stories

iOS 18 Apple Music Messages and Notes Feature 1

iOS 18 Rumored to Add New Features to These 16 Apps on Your iPhone

Tuesday April 30, 2024 10:44 am PDT by
Apple is expected to announce iOS 18 during its WWDC keynote on June 10, and new features have already been rumored for many apps, including Apple Music, Apple Maps, Calculator, Messages, Notes, Safari, and others. Below, we recap iOS 18 rumors on a per-app basis, based on reports from MacRumors, Bloomberg's Mark Gurman, and others: Apple Maps: At least two new Apple Maps features are...
apple watch ipad demo 1

Check Out This Apple Watch iPad Demo Unit From 2014

Wednesday May 1, 2024 1:46 pm PDT by
With the 10th anniversary of the Apple Watch approaching, we thought it would be fun to take a look back at an interesting bit of Apple Watch history. After the Apple Watch was announced in 2014, and before it became available in 2015, Apple sent out custom Apple Watch iPad demo kiosks to retail stores. The Apple Watch and iPad units used for these devices were specially designed, had custom ...
maxresdefault

Will the New iPad Pro Really Have the M4 Chip?

Wednesday May 1, 2024 8:30 am PDT by
While Apple's upcoming iPad Pro models have been expected to feature the M3 chip for over a year, recent reports have unexpectedly suggested that the new devices will instead feature the as-yet-unannounced M4 chip. Subscribe to the MacRumors YouTube channel for more videos. Last week, Bloomberg's Mark Gurman said that he now believes there is a "strong possibility" that the upcoming iPad Pro ...
Apple CarPlay Dash

Report Examines GM's Controversial Move to Abandon Apple CarPlay

Wednesday May 1, 2024 4:53 am PDT by
An in-depth Bloomberg report today resurfaced General Motors' decision to replace Apple CarPlay with its own software. Last year, GM announced that it planned to forgo Apple CarPlay in its new electric vehicles, starting with the 2024 Chevrolet Blazer EV. Instead, the automaker introduced a proprietary infotainment platform, aiming to control and customize the digital experience within its...
Apple Watch Ultra 2 hero feature blorange

Kuo: Apple Watch Ultra to Get 'Almost No' Hardware Upgrades This Year

Wednesday May 1, 2024 6:53 am PDT by
Just over six months ago, Apple supply chain analyst Ming-Chi Kuo said the likelihood of a new Apple Watch Ultra being released in 2024 was "decreasing," but it now sounds like there will be an Apple Watch Ultra 3 this year after all. In a direct message shared with MacRumors today, Kuo said that while the Apple Watch Ultra will be updated this year, the new model will have "almost no"...
maxresdefault

Apple Announces 'Let Loose' Event on May 7 Amid Rumors of New iPads

Tuesday April 23, 2024 7:11 am PDT by
Apple has announced it will be holding a special event on Tuesday, May 7 at 7 a.m. Pacific Time (10 a.m. Eastern Time), with a live stream to be available on Apple.com and on YouTube as usual. The event invitation has a tagline of "Let Loose" and shows an artistic render of an Apple Pencil, suggesting that iPads will be a focus of the event. Subscribe to the MacRumors YouTube channel for more ...