A new data breach on Facebookresulted from a bug in the Photo API, which allowed app developers to access photos of 5.6 million users.
The bug gave access to timeline photos, Facebook stories, Marketplace photos, and even photos that users uploaded to Facebook that they never intended to share.
According to Facebook, the bug started on September 13th and ran for 12 days until the company discovered it on September 25th.
Facebook then notified the European Data Protection Commissioner (IDPC) of the data breach on November 22. The privacy officer launched a legal investigation into the matter.
Facebook's official statement said: "We currently believe the bug may have affected up to 6.8 million users and up to 1,500 apps built by 876 developers. The only apps affected by this bug were those that Facebook approved to access the Photos API and that users have authorized to access their photos."
After apologizing, Facebook said it would develop a tool for app developers to help them identify users who may have been affected by this privacy breach.
Facebook will also notify users who have been affected by the Photo API bug in the coming days.
Currently, the company has not revealed the names of the apps that have access to users' photos, and there is no official count of the number of photos that have been compromised.
Facebook seems to be going through one of its worst phases with data breaches occurring one after another and reports of internal conflicts due to poor management of issues by its executives.
