HomeSecurityInstagram vulnerability that allowed private photos to be exposed has been fixed

A vulnerability in Instagram that allowed private photos to be exposed was fixed

0_600_800_0_70_http---i.haymarket.net.au-News-instagram hack security infosec

White hat hacker Christian Lopez Martin has identified a vulnerability in the popular social network Instagramthat could be exploited by attackers to modify the privacy settings of any account, in order to convert private photos to public ones, or convert popular pages to private ones.

Such attacks are carried out through malicious phishing links, which exploit vulnerabilities such as Cross-site request forgery (CSRF).

A similar vulnerability was also identified in its mobile application by researcher Christian Lopez Martin.

"A successful exploitation of the CSRF vulnerability could compromise any user's data (photos and personal information), making their Instagram profile public," Martin said in a blog post.

"It is important to mention that the vulnerability was fully exploitable in a real-world scenario, as Instagram had not taken the necessary protective measures to prevent this type of attack.".

The researcher notified Facebook, which has acquired Instagram, in August, and the first attempt to patch the vulnerability was made by the social network in September.

The hacker, however, managed to bypass the first patch issued by Facebook to address the vulnerability, and the flaw on Instagram was finally closed last week.

Martin has discovered significant security vulnerabilities in websites and applications of major companies, including Apple, Google, Ebay and Microsoft.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS