A bug in a new central system Meta created for users to manage their Facebook and Instagram logins could have allowed malicious hackers to disable an account's two-factor authentication (2FA) simply by knowing their phone number.

Gtm Mänôz, a security researcher from Nepal, noticed that Meta had not set a limit on the attempts a user can enter the two-factor code needed to log in to their accounts in the new Meta Accounts Center, which helps users connect all their Meta accounts, such as Facebook and Instagram.
See also: Meta: Donald Trump will return to Facebook and Instagram
However, with a victim's phone number, a hacker could go to the centralized accounts center, enter the victim's phone number, link that number to their own Facebook account, and then brute force the password. This was the key step, because there was no upper limit to the number of attempts someone could make.
A successful attack would result in Meta sending a message to the victim, saying that two-factor authentication (2FA) for their Facebook or Instagram account has been disabled because their phone number was linked to someone else's account.
See also: Seattle: Schools sue TikTok, Facebook, Instagram and Snapchat
“Basically the biggest issue here was the rollback of SMS-based 2FA, just knowing (the victim’s) phone number ,” Mänôz told TechCrunch.
At this point, an attacker could try to take over the victim's Facebook account by phishing for the password ,since the target no longer had two-factor authentication (2FA) enabled.
The security researcher found the bug in Meta Accounts Center last summer and reported it to the company in mid-September. Meta fixed the bug shortly after and paid Mänôz $27,200 for reporting the bug.

Meta spokesperson Gabby Curtistold TechCrunch that when the bug was discovered, the new login system was still in a small public test phase. Meta reportedly conducted an investigation after the bug was reported and found no evidence that the bug had been exploited.
See also: Instagram launches 'quiet mode' to take a break from the app
Two-factor authentication (2FA) adds an extra layer of security by requiring users to provide not only their usernames and passwords, but also additional information, such as a one-time code sent via SMS, before they are granted access. This makes it much harder for malicious actors who may have obtained your login details through phishing attacks or other means to gain unauthorized access. However, we must always be on guard, because as was the case with the bug affecting Facebook accounts, 2FA can sometimes be disabled.
Source: techcrunch.com
