Researchers identified a gap in the contact discovery system that allowed anyone's phone number to be verified without limit. This issue was first reported in 2017, but Meta did not implement a fix. A team from the University of Vienna demonstrated that the vulnerability was still active, managing to collect 30 million numbers from the U.S. in just 30 minutes. Although Meta later implemented rate limits to prevent such attacks, researchers ensured that the data was responsibly erased.
Meta acknowledged the collaboration and stated that there was no evidence that malicious actors exploited this vulnerability, emphasizing that users' messages remain protected by end-to-end encryption.
Latest News
23:05
23:03
22:55
22:48
22:44
See more news