Facebook a Facebook application (such as Candy Crush Saga, Lexulous Word Game), which provides them with temporary and secure access to the Facebook API.
To make this possible, users must “allow or accept” the app’s request so that an app can access account information with the required permissions.
The Access Token stores information about the permissions that have been granted, as well as information about when it will expire and which application caused it. Approved Facebook applications can post or delete content to the user's account using the access details rather than the password from Facebook.
Access Tokens are quite sensitive, because anyone who knows a user's access token can access the user's data and can perform any action on behalf of the user, until the token is deactivated.
Facebook's Security team has identified a vulnerability filed by Ahmed Elsobky, a security expert from Egypt, and states that "we are working to mitigate the threat when it comes to our official apps, since they are pre-approved. For other apps, unfortunately, it cannot be completely blocked, as this would mean that any website that works with Facebook must use HTTPS, which is not feasible at the moment."
The attack was carried out via Man-in-the-Middle and is shown below:

