← BACK TO FEED
TAG

bug bounty3 articles

Researcher Pockets $78k After Finding Meta Support Data Wide Open

Security researcher Rony K Roy received a $78,000 bug bounty from Meta after discovering a critical vulnerability in Meta's backend support infrastructure, initially identified in January 2026. The flaw combined missing authorization, broken access control, and IDOR issues that, when chained together, could have allowed attackers to access sensitive customer support data, including emails, chat logs, and personal information shared with Meta support. Meta patched the vulnerability in April 2026 and found no evidence of malicious exploitation prior to the fix.

22 Jul 2026

Opera GX's Mod Auto-Installer Let Attackers Silently Steal Your Gmail Address With Pure CSS

Researchers discovered a critical flaw in Opera GX that allowed malicious websites to silently auto-install a browser mod (a cosmetic add-on) without any user interaction or approval, then exploit it to steal data from other sites the victim visited. By packing the mod with ~150,000 CSS rules, attackers could reconstruct sensitive information like a Gmail address character by character through a cross-site leak technique, all within seconds of the victim landing on the malicious page. Opera has patched the vulnerability in version 130.0.5847.89, rated it their highest severity (P1), and paid the maximum $5,000 bounty, though the underlying auto-install behavior had been flagged as a risk since 2023.

11 Jul 2026

Chrome Vulnerability Numbers Are Skyrocketing. AI Is Almost Certainly Why.

Google has seen a dramatic surge in Chrome vulnerability discoveries, with the number of internally found flaws jumping from a handful in March to 100 in a single advisory published on May 5, likely due to its use of AI tools. While Google has not explicitly confirmed AI is responsible, the timing aligns with its own statements that AI and automation are helping its teams remediate risks "at an unprecedented rate." Google has been developing AI-powered vulnerability discovery tools such as Big Sleep and CodeMender, and is also among a select group of organisations with access to Anthropic's powerful Claude Mythos model.

23 May 2026