← BACK TO FEED
Metabug bountyIDORaccess controlvulnerability disclosure

Researcher Pockets $78k After Finding Meta Support Data Wide Open

Security researcher Rony K Roy received a $78,000 bug bounty from Meta after discovering a critical vulnerability in Meta's backend support infrastructure, initially identified in January 2026. The flaw combined missing authorization, broken access control, and IDOR issues that, when chained together, could have allowed attackers to access sensitive customer support data, including emails, chat logs, and personal information shared with Meta support. Meta patched the vulnerability in April 2026 and found no evidence of malicious exploitation prior to the fix.

A security researcher has walked away with a $78,000 bounty from Meta after uncovering a vulnerability that exposed customer support data across the company's backend infrastructure.

Rony K Roy, an independent researcher, flagged the issue to Meta in January 2026. His initial report painted it as fairly routine, but the more he dug, the worse it got. By the time the full picture emerged, what started as a modest authorization concern had ballooned into something considerably more serious.

Meta pushed out patches in April and says it found no evidence of anyone exploiting the flaw before it was fixed.

Roy went public with his findings last week and confirmed to SecurityWeek that the $78,000 payout was his. Meta didn't respond to requests for comment, though Roy's name does appear near the top of the company's 2026 bug bounty leaderboard, which does rather speak for itself.

The vulnerability originated in Meta Horizon Managed Solutions, an enterprise platform used to manage Meta Quest devices and users. Roy initially suspected a straightforward authorization flaw, but it turned out to be a symptom of deeper problems in Meta's support infrastructure.

The full chain involved missing authorization checks, broken access controls, and an insecure direct object reference (IDOR) flaw. Individually annoying. Together, genuinely nasty.

Chained correctly, an attacker could have enumerated Meta support case numbers and pulled the associated data. That means email and chat logs between users and Meta support, full case details, files uploaded through support requests, and personal contact information users had handed over in good faith.

It gets worse. The same exploit path could have let an attacker create support tickets on behalf of organisations using Meta Horizon Managed Solutions, tamper with case workflows including flipping case statuses, and add themselves as unauthorised subscribers to existing support cases.

So: read access to sensitive conversations, write access to support workflows, and the ability to impersonate enterprise customers. Not a great combination.

Meta's bug bounty programme continues to attract serious researchers, which is presumably the point. Whether $78,000 reflects the true potential impact of this particular flaw is a question worth asking, but Roy presumably isn't complaining.

READ NEXT
ServiceNow RCE Flaw Exploited Within Days of Patch — But Who's Actually Behind It?Roundup: Iranian Spooks Track US Troops Via Ad Data, macOS Malware Plays Dead, and a Textile Firm Goes Bust After Six Weeks of Ransomware HellOpera GX's Mod Auto-Installer Let Attackers Silently Steal Your Gmail Address With Pure CSS