HomeinetBitdefender: Facebook Social Login vulnerability

Bitdefender: Facebook Social Login vulnerability

Bitdefender has identified a flaw in the Facebook account registration process that indirectly allows attackers to gain access to user profiles on websites that have the Facebook Social Login feature enabled.facebook bug

The vulnerability could be exploited if an attacker discovered that the victim has an email address that they use on a regular basis, but have not registered with Facebook to create an account.

The attacker could create a Facebook profile with the victim's email address, and when Facebook asks them to verify their identity, the attacker adds their own email account as a secondary email address.

The attacker could then use the primary email address (the victim's address) with the secondary email address (their own address) to get Facebook to verify the account.

Facebook will "see" that the account was verified, even if only the secondary email address was used and not the primary one (of the victim).

Although it seems like a simple flaw in Facebook's sign-up process, in reality, it's not. Because of Facebook's Social Login feature that allows users to sign up and log in to other websites, using their Facebook account with an email address belonging to someone else is dangerous.

Imagine if the victim had an account on an online store or business management portal where the Facebook Social Login feature is enabled. The attacker could automatically log in using the victim's profile.

Bitdefender researchers informed Facebook about the vulnerability.

Bitdefender

 

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS