The Bug Exposed Facebook Users And Their Friends’ Interests Was Fixed Shortly After
Author - Nov 15, 2018
Malicious websites exploited a bug on the Facebook website to see users’ likes and interests while they had no idea.
- Instagram Launches A Lite Version For Users In Rural And Remote Areas
- Australia Passed New Law That Requires Facebook And Google To Pay For News Content
- Facebook Stops Showing Australian Content, Even From Government Sites
Facebook has seemingly had a year full of difficulties when facing the scandals including security breaches and hacks. A security researcher recently revealed another bad luck for the company.
As per this revelation, malicious websites exploited a bug on the website Facebook.com to see users’ likes and interests while they had no idea.
Ron Masas, a security researcher of Imperva detected the bug in May 2018. He reportedly uncovered that search results on Facebook were the key reason for the attacks of Cross-Site Request Forgery (CSRF for short).
CSRF, also known as Sea Surfing, is a type of attack that the web browser is cheated to run a task inside an application logged in by users. As a consequence, the attack will affect both end users and businesses.
In the case of Facebook, user’s data was siphoned on another browser tab and then, an IFrame could be embedded by a website to make use of their data while they were unaware.
He further explained that the IFrame HTML document was used to “allow information to cross over domains”. In other words, hackers could use Facebook to gather all the information relating to users and their friends when they accessed to a suspicious website.
Moreover, the website approached the search queries on Facebook in a new tab and hence, when users liked a page, hackers would get the information. The same thing also happened when hackers used certain keywords to search any post given by the users which only their Facebook friends can see.
Even when users set the privacy settings to hide their own interests to everyone, but their friends, it doesn’t work with the bug. Advertisement companies may be the beneficiary in this scenario.
The good news is that the company rapidly fixed this bug as soon as it came to light a few days later.
The Facebook spokesperson claimed that the company sent a warning to browsers makers as well as web standards groups to prevent this bug from attacking other web applications.
Featured Stories
ICT News - Feb 19, 2026
Escalating Costs for NVIDIA RTX 50 Series GPUs: RTX 5090 Tops $5,000, RTX 5060 Ti...
ICT News - Feb 18, 2026
Google's Project Toscana: Elevating Pixel Face Unlock to Rival Apple's Face ID
Mobile - Feb 16, 2026
Xiaomi Launches Affordable Tracker to Compete with Apple's AirTag
ICT News - Feb 15, 2026
X Platform Poised to Introduce In-App Crypto and Stock Trading Soon
ICT News - Feb 13, 2026
Elon Musk Pivots: SpaceX Prioritizes Lunar Metropolis Over Martian Colony
ICT News - Feb 10, 2026
Discord's Teen Safety Sham: Why This Data Leak Magnet Isn't Worth Your Trust...
ICT News - Feb 09, 2026
PS6 Rumors: Game-Changing Specs Poised to Transform Console Play
ICT News - Feb 08, 2026
Is Elon Musk on the Path to Becoming the World's First Trillionaire?
ICT News - Feb 07, 2026
NVIDIA's Gaming GPU Drought: No New Releases in 2026 as AI Takes Priority
ICT News - Feb 06, 2026
Elon Musk Clarifies: No Starlink Phone in Development at SpaceX
Read more
Mobile- Feb 17, 2026
Anticipating the Samsung Galaxy S26 and S26+: Key Rumors and Specs
The Samsung Galaxy S26 series is on the horizon, sparking excitement among tech enthusiasts.
ICT News- Feb 18, 2026
Google's Project Toscana: Elevating Pixel Face Unlock to Rival Apple's Face ID
As the smartphone landscape evolves, Google's push toward superior face unlock technology underscores its ambition to close the gap with Apple in user security and convenience.
ICT News- Feb 19, 2026
Escalating Costs for NVIDIA RTX 50 Series GPUs: RTX 5090 Tops $5,000, RTX 5060 Ti Closes in on RTX 5070 Pricing
As the RTX 50 series continues to push boundaries in gaming and AI, these price trends raise questions about accessibility for average gamers.


Comments
Sort by Newest | Popular