Researcher Pockets $78k After Finding Meta Support Data Wide Open
A security researcher has walked away with a $78,000 bounty from Meta after uncovering a vulnerability that exposed customer support data across the company's backend infrastructure.
Rony K Roy, an independent researcher, flagged the issue to Meta in January 2026. His initial report painted it as fairly routine, but the more he dug, the worse it got. By the time the full picture emerged, what started as a modest authorization concern had ballooned into something considerably more serious.
Meta pushed out patches in April and says it found no evidence of anyone exploiting the flaw before it was fixed.
Roy went public with his findings last week and confirmed to SecurityWeek that the $78,000 payout was his. Meta didn't respond to requests for comment, though Roy's name does appear near the top of the company's 2026 bug bounty leaderboard, which does rather speak for itself.
The vulnerability originated in Meta Horizon Managed Solutions, an enterprise platform used to manage Meta Quest devices and users. Roy initially suspected a straightforward authorization flaw, but it turned out to be a symptom of deeper problems in Meta's support infrastructure.
The full chain involved missing authorization checks, broken access controls, and an insecure direct object reference (IDOR) flaw. Individually annoying. Together, genuinely nasty.
Chained correctly, an attacker could have enumerated Meta support case numbers and pulled the associated data. That means email and chat logs between users and Meta support, full case details, files uploaded through support requests, and personal contact information users had handed over in good faith.
It gets worse. The same exploit path could have let an attacker create support tickets on behalf of organisations using Meta Horizon Managed Solutions, tamper with case workflows including flipping case statuses, and add themselves as unauthorised subscribers to existing support cases.
So: read access to sensitive conversations, write access to support workflows, and the ability to impersonate enterprise customers. Not a great combination.
Meta's bug bounty programme continues to attract serious researchers, which is presumably the point. Whether $78,000 reflects the true potential impact of this particular flaw is a question worth asking, but Roy presumably isn't complaining.