Researcher nets major reward for finding Facebook bug able to unlock the gates to its internal systems

Facebook on laptop
(Image credit: Luca Sammarco/Pexels)

  • A security flaw found in Facebook's ad platform has been fixed by Meta
  • The researcher who discovered the flaw was awarded a $100,000 bug bounty
  • The flaw allowed the researcher to effectively take control of a Facebook server

Meta has awarded cybersecurity researcher Ben Sadeghipour a bug bounty of $100,000 after he discovered a security vulnerability on Facebook’s ad platform in October 2024.

The flaw allowed Sadeghipour to run commands on the internal Facebook server which housed the platform, giving him control of the server.

According to Sadeghipour, the unpatched bug allowed him to hijack the server using a headless Chrome browser, which is a version of the browser users run from the computer’s terminal, to interact with Facebook’s internal servers directly.

Part of wider researcher

The flaw in the platform was connected to a server that Facebook used to create and deliver ads, which was vulnerable to a previously fixed flaw found in the Chrome browser, which Facebook uses in its ad system.

Sadeghipour told TechCrunch online advertising platforms are attractive targets because “there’s so much that happens in the background of making these ‘ads’ — whether they are video, text, or images.”

“But at the core of it all it’s a bunch of data being processed on the server-side and it opens up the door for a ton of vulnerabilities,” Sadeghipour said.

The researcher confirms he didn’t test out everything he could have once he was inside the server, although “what makes this dangerous is this was probably a part of an internal infrastructure.”

After reporting the vulnerability to Meta, the bug took just an hour to fix, Sadeghipour said, noting his discovery was part of ‘ongoing research on a specific application with a specific purpose’. This flaw in particular took him a few hours to identify, but Meta worked with him to quickly patch the bug and offered a bounty that was ‘way beyond’ expectations, he confirmed in a LinkedIn post.

Bug bounties have been on the rise recently, with Google drastically increasing its rewards for researchers who participate in the program, so security research is getting more lucrative.

You might also like

Ellen Jennings-Trace
Staff Writer

Ellen has been writing for almost four years, with a focus on post-COVID policy whilst studying for BA Politics and International Relations at the University of Cardiff, followed by an MA in Political Communication. Before joining TechRadar Pro as a Junior Writer, she worked for Future Publishing’s MVC content team, working with merchants and retailers to upload content.

Read more
A woman at a table using a Windows laptop, opposite sits a man, neither show their face
Microsoft will now pay you even more to find security bugs in Copilot
the YouTube logo on a screen in front of other YouTube logos covering a black background
Worrying YouTube security flaw exposed billions of user emails
Location Data
Cloudflare CDN flaw could expose user location simply by sending an image
The best free firewall
Microsoft fixes Power Pages security flaw, tells users to be on their guard
A person at a laptop with a cybersecure lock symbol floating above it.
A worrying security flaw could have left Microsoft SharePoint users open to attack
A person holding out their hand with a digital AI symbol.
Meta Llama LLM security flaw could let hackers easily breach systems and spread malware
Latest in Security
Representational image of a cybercriminal
Criminals are spreading malware disguised as DeepSeek AI
healthcare
Software bug meant NHS information was potentially “vulnerable to hackers”
A hacker wearing a hoodie sitting at a computer, his face hidden.
Experts warn this critical PHP vulnerability could be set to become a global problem
botnet
YouTubers targeted by blackmail campaign to promote malware on their channels
A close-up of a phone screen showing the Telegram, Signal and WhatsApp apps
Agentic AI has “profound” issues with security and privacy, Signal President says
botnet
Another top security camera maker is seeing devices hijacked into botnet
Latest in News
Nintendo Switch 2
A Nintendo Switch 2 FCC filing confirms Wi-Fi 6 and NFC support for the upcoming console
Google Pixel 8 review Pixel 8 Pro cameras
Is your Google Pixel 9 screen flickering or are the haptics a lot more intense? You aren't alone, and thankfully there's a fix
Motorola Edge 50 Pro lavender
Your next Android bargain? Major Motorola leak teases details of multiple 2025 phones – including the Edge 60 series
Matt Murdock holding a phone to his right ear in a prison in Daredevil: Born Again episode 2
What time is Daredevil: Born Again episode 3 going to be released on Disney+?
A close-up of the PS5 Pro
PS5 Pro games will soon get something 'very similar' to FSR 4 for what Sony is calling 'the next evolution of PSSR'
Representational image of a cybercriminal
Criminals are spreading malware disguised as DeepSeek AI