The Bug Exposed Facebook Users And Their Friends’ Interests Was Fixed Shortly After
Author - Nov 15, 2018
Malicious websites exploited a bug on the Facebook website to see users’ likes and interests while they had no idea.
- Instagram Launches A Lite Version For Users In Rural And Remote Areas
- Australia Passed New Law That Requires Facebook And Google To Pay For News Content
- Facebook Stops Showing Australian Content, Even From Government Sites
Facebook has seemingly had a year full of difficulties when facing the scandals including security breaches and hacks. A security researcher recently revealed another bad luck for the company.
As per this revelation, malicious websites exploited a bug on the website Facebook.com to see users’ likes and interests while they had no idea.
Ron Masas, a security researcher of Imperva detected the bug in May 2018. He reportedly uncovered that search results on Facebook were the key reason for the attacks of Cross-Site Request Forgery (CSRF for short).
CSRF, also known as Sea Surfing, is a type of attack that the web browser is cheated to run a task inside an application logged in by users. As a consequence, the attack will affect both end users and businesses.
In the case of Facebook, user’s data was siphoned on another browser tab and then, an IFrame could be embedded by a website to make use of their data while they were unaware.
He further explained that the IFrame HTML document was used to “allow information to cross over domains”. In other words, hackers could use Facebook to gather all the information relating to users and their friends when they accessed to a suspicious website.
Moreover, the website approached the search queries on Facebook in a new tab and hence, when users liked a page, hackers would get the information. The same thing also happened when hackers used certain keywords to search any post given by the users which only their Facebook friends can see.
Even when users set the privacy settings to hide their own interests to everyone, but their friends, it doesn’t work with the bug. Advertisement companies may be the beneficiary in this scenario.
The good news is that the company rapidly fixed this bug as soon as it came to light a few days later.
The Facebook spokesperson claimed that the company sent a warning to browsers makers as well as web standards groups to prevent this bug from attacking other web applications.
Featured Stories
ICT News - Jul 05, 2025
Windows 11 is Now the Most Popular Desktop OS in the World
ICT News - Jul 02, 2025
All About Florida’s Alligator Alcatraz: A Smart Move for Immigration Control
ICT News - Jun 25, 2025
AI Intimidation Tactics: CEOs Turn Flawed Technology Into Employee Fear Machine
ICT News - Jun 24, 2025
Tesla Robotaxi Finally Hits the Streets: $4.20 Rides That'll Make You Hold Your...
ICT News - Jun 24, 2025
World's First Flying Humanoid Robot Takes Flight
ICT News - Jun 24, 2025
When Closed Source Met Open Source: Bill Gates Finally Meets Linus Torvalds After...
Gadgets - Jun 23, 2025
COLORFUL SMART 900 AI Mini PC: Compact Power for Content Creation
ICT News - Jun 22, 2025
Neuralink Telepathy Chip Enables Quadriplegic Rob Greiner to Control Games with...
ICT News - Jun 20, 2025
Tesla vs Zoox vs Waymo: Who would win?
ICT News - Jun 19, 2025


Comments
Sort by Newest | Popular