writeups.xyz writeups.xyz / Meta / Facebook

Title Vulnerabilities Programs Authors
Disclosing Facebook page admins by playing a game
Two Factor Authentication Bypass On Facebook
Meta Quest: Attacker could make any Oculus user to follow (subscribe) him without any approval
Instagram vulnerability : Turn off all type of message requests using deeplink (Android)
0 click Facebook Account Takeover and Two-Factor Authentication Bypass
Delete any Video or Reel on Facebook (11,250$)
[WRITE-UP] Irremovable comments on the FB Lite app | A story of a simple FB Lite bug that I found just by observation (Bounty: 500 USD)
Header spoofing via a hidden parameter in Facebook Batch GraphQL APIs
Facebook SMS Captcha Was Vulnerable to CSRF Attack
Details about future collaboration profiles and pages have been revealed
Group expert's pending expertise request leaking on Facebook
Zuckerpunch - Abusing Self Hosted Github Runners at Facebook
Viewing Instagram live streams anonymously without notifying the host
Email Confirmation bypass at Instagram
iOS Privacy: Instagram and Facebook can track anything you do on any website in their in-app browser
Irremovable guest in facebook event — Facebook bug bounty
Multiple Open URL Redirection Vulnerability on Facebook worth $1500
Instagram photo was present in data backup nearly after two years being deleted.
Permanent Crash Instagram Followers.
React debug.keystore key was trusted by Meta(Facebook) which caused to Instagram account takeover by malicious apps.
Hacking Facebook Invoice: How I could’ve bought anything for Free from Facebook Business Pages
Facebook Portal’s business logic error lead to 500$
The Army Of The Headless Browsers
How I found a Critical Bug in Instagram and Got 49500$ Bounty From Facebook
Same bug different platform