Facebook eliminated potential 'webcam spying' hack this summer

Facebook eliminated potential 'webcam spying' hack this summer
No webcams were hacked, Facebook claims

A Facebook security vulnerability, which could have been exploited to activate a user's webcam and record them without their knowledge, was closed off this summer, it has been revealed.

Facebook paid Indian research firm XY Security a $2,500 (UK£1,546, AUD$2,409) "bounty" in July for discovering the issue and drawing the bug to its attention, the social network has confirmed.

The flaw, which Facebook said had never exploited by a potential 'Peeping Tom', could, conceivably have troubled users who had already agreed to give Facebook permission to access the camera.

Beyond that the user would have to be 'tricked' into visiting a malicious page, then agree to activate the camera - allowing the spy/pervert to begin recording.

Five times the going rate

Facebook must have felt the threat was serious at it paid five times its usual rate to the two researchers who reported the flaw.

"This vulnerability, like many others we provide a bounty for, was only theoretical, and we have seen no evidence that it has been exploited in the wild," Facebook spokesperson Josh Wolens told Bloomberg.

"Essentially, several things would need to go wrong - a user would need to be tricked into visiting a malicious page and clicking to activate their camera, and then after some time period, tricked into clicking again to stop/publish the video."

Facebook is one of many Silicon Valley heavyweights (other notables being Google and Mozilla) who offer 'bug bounties', paying out millions to researchers who spot flaws and potential dangers.

Chris Smith

A technology journalist, writer and videographer of many magazines and websites including T3, Gadget Magazine and TechRadar.com. He specializes in applications for smartphones, tablets and handheld devices, with bylines also at The Guardian, WIRED, Trusted Reviews and Wareable. Chris is also the podcast host for The Liverpool Way. As well as tech and football, Chris is a pop-punk fan and enjoys the art of wrasslin'.

Latest in Facebook
 Facebook social media app logo on log-in, sign-up registration page
How to delete all your Facebook posts
The Meta logo on a smartphone in front of the Facebook logo a little bit blurred in the background
Meta's new 'Link History' feature for the Facebook app isn't as protective of your data as it claims
The Meta Quest 3 in action
How much more data can Meta collect? Probably a lot, thanks to the Meta Quest 3 and Ray-Ban smart glasses
A laptop screen showing a Facebook Groups page
Scam alert: how to spot hoax posts in your Facebook Groups
Facebook
Facebook Messenger is losing a useful messaging feature soon
mother watching her daughter's activity online
Meta's new Facebook parental controls show social media still doesn't like responsibility
Latest in News
A young woman is working on a laptop in a relaxed office space.
I’ll admit, Microsoft’s new Windows 11 update surprised me with its usefulness, providing accessibility fixes, a gamepad keyboard layout, and PC spec cards
inZOI promotional material.
inZOI has become the most wishlisted game on Steam, but I wouldn't get too caught up in the hype
Xbox Series X and Xbox wireless controller set to a green background
Xbox Insiders are currently testing a new Game Hub feature that looks useful, but I've got mixed feelings about it
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Nespresso Vertuo Pop machine in Candy Pink with coffee drinks and capsules
My favorite Nespresso coffee maker just got a fresh new makeover, and now I love it even more
Microsoft Surface Laptop and Surface Pro devices on a table.
Hate Windows 11’s search? Microsoft is fixing it with AI, and that almost makes me want to buy a Copilot+ PC