A security researcher has published detailed evidence showing that some private Instagram profiles were returning links to user photos to unauthenticated visitors.
See also: Instagram data leak: Platform says there was no breach

Instagram's private account feature is designed to limit photos, videos, stories, and reels to only approved followers. However, the researcher's findings show that, in some cases, content from private profiles was embedded in publicly accessible server responses.
According to the researcher, Meta fixed the issue after his report was submitted, but later closed it as “not applicable,” stating that the vulnerability could not be reproduced.
Security researcher Jatin Banga recently showed how some private Instagram profiles were leaking links to private photos from those accounts — in the body of the HTML response.
When an unauthenticated user accesses certain mobile devices, private profiles on Instagram display the standard message: “This account is private. Follow to see their photos and videos.” However, in the HTML source code for the affected profiles, links to some private photos were embedded in the page response.
See also: Instagram solves the problem with password reset emails

In Banga's example , the polaris_timeline_connection JSON object returned in the HTML contained encoded CDN links to photos that shouldn't be accessible. The PoC video shared by Banga shows the data leak in action.
Limiting the test to private profiles he had created or had explicit permission to use, Banga found that at least 28% of the profiles returned links to private photos.
The researcher says he shared his findings with Instagram’s parent company, Meta, as early as October 12, 2025.Meta initially categorized the issue as a CDN caching issue, a characterization the researcher disputed. “This was not a CDN caching issue — Instagram’s backend failed to check authorization before populating the response,” Banga wrote, describing it as a server-side authorization failure.
Banga created a second bug report clarifying the issue but was unable to reach a satisfactory resolution with Meta despite a lengthy discussion that lasted days. According to the researcher, after repeated exchanges, the case was closed as “not applicable” but the exploit stopped working around October 16.
See also: Instagram gives you more control over its Reels algorithm

In addition to his disclosure and the GitHub repository documenting extensive evidence of the flaw and communications with Meta, Banga shared additional material to prove the existence of the flaw.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
