In recent years, Facebook has identified several vulnerabilities in third-party products, which the company's security team always reports to their respective owners.

However, while in some cases the bugs have been fixed within a few days by the respective developers, in others Facebook has been forced to fix the code itself or develop its own internal alternatives for a product.
But the company believes this is not fair to users, since most will continue to use unupdated products.
For this reason, Facebook has decided to implement a new policy.
It's called the "vulnerability disclosure policy" and it's a set of rules that Facebook engineers will apply when reporting vulnerabilities they discover in third-party products.
According to a summary of these new rules, Facebook promises to “make reasonable efforts to find the right contact for reporting a vulnerability” in any third-party product.
After contacting the appropriate person, Facebook says it will provide an in-depth technical report describing the bug, but if a company/developer doesn't acknowledge receiving the report within 21 days, its engineers will publicly disclose the details of the bugs online sothat other users/developers can protect their products.
Companies/developers who receive reports will have 90 days to resolve the issues. While some companies may be given more time, once that period is up, Facebook will publish details of the bugs and allow users and companies to mitigate the bugs as they see fit.
The only case where Facebook will immediately publicize a bug is when it is actively exploited, and only in cases where such disclosure can help users.
Facebook hopes that these new practices will help fix bugs more quickly and effectively and provide greater security for users.
You can see the new rules in more detail here.
