Facebook security flaw exposes private photos

Facebook
Photos of Mark Zuckerberg about to slay a chicken for food have been revealed

Facebook has moved quickly to lockdown a security flaw which briefly allowed users to see your private photo albums, just by reporting a public photo as containing nudity.

As a means of making his point, the hacker was able to exploit the flaw to access the private albums of Facebook CEO Mark Zuckerberg before posting them online.

Prior to the fix, it seems that reporting a photo as nudity or pornography would allow you to view other photos listed as private.

The idea was to enable the offended party to make the social network aware of further lewd pictures.

Just a bug, says Facebook

A Facebook spokesperson admitted the flaw to Gizmodo, attributing the security lapse to a bug in a recent code push.

The statement said: "Earlier today, we discovered a bug in one of our reporting flows that allows people to report multiple instances of inappropriate content simultaneously.

"The bug allowed anyone to view a limited number of another user's most recently uploaded photos irrespective of the privacy settings for these photos.

"This was the result of one of our recent code pushes and was live for a limited period of time. Upon discovering the bug, we immediately disabled the system, and will only return functionality once we can confirm the bug has been fixed."

This revelation was the last thing that Facebook needed following its reprimand from the FTC in the United States over a series of privacy violations.

Chris Smith

A technology journalist, writer and videographer of many magazines and websites including T3, Gadget Magazine and TechRadar.com. He specializes in applications for smartphones, tablets and handheld devices, with bylines also at The Guardian, WIRED, Trusted Reviews and Wareable. Chris is also the podcast host for The Liverpool Way. As well as tech and football, Chris is a pop-punk fan and enjoys the art of wrasslin'.

Latest in Facebook
 Facebook social media app logo on log-in, sign-up registration page
How to delete all your Facebook posts
The Meta logo on a smartphone in front of the Facebook logo a little bit blurred in the background
Meta's new 'Link History' feature for the Facebook app isn't as protective of your data as it claims
The Meta Quest 3 in action
How much more data can Meta collect? Probably a lot, thanks to the Meta Quest 3 and Ray-Ban smart glasses
A laptop screen showing a Facebook Groups page
Scam alert: how to spot hoax posts in your Facebook Groups
Facebook
Facebook Messenger is losing a useful messaging feature soon
mother watching her daughter's activity online
Meta's new Facebook parental controls show social media still doesn't like responsibility
Latest in News
Zendesk Relate 2025
Zendesk Relate 2025 - everything you need to know as the event unfolds
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Google Gemini AI
Gemini can now see your screen and judge your tabs
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Philips Hue
Philips Hue might be working on a video doorbell, and according to a new report, we just got our first look at it
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand