Meta AI Vulnerability That Could Leak Users’ Private Conversations Fixed: Report

The vulnerability in Meta AI was reportedly discovered by Sandeep Hodkasia, founder of AppSecure.

Advertisement
Written by Akash Dutta, Edited by Siddharth Suvarna | Updated: 16 July 2025 17:45 IST
Highlights
  • The researcher reportedly found a way to manipulate AI chats’ unique ID
  • Meta reportedly paid the researcher $10,000 for finding the flaw
  • Meta AI chatbots can now send users proactive follow-up messages

A fix for the bug was said to be implemented by Meta in January

Photo Credit: Reuters

Meta AI reportedly had a vulnerability that could be exploited to access other users' private conversations with the chatbot. Accessing this bug did not require breaking into Meta's servers or manipulating the code of the app; instead, it could be triggered by just analysing the network traffic. As per the report, a researcher found the bug late last year and informed the Menlo Park-based social media giant about it. The company then deployed a fix to the issue in January, and rewarded the researcher for finding the exploit.

Meta Fixes a Bug That Could Have Compromised Users' Private Data

According to a TechCrunch report, the Meta AI vulnerability was discovered by Sandeep Hodkasia, founder of AppSecure, a security testing firm. The researcher reportedly informed Meta about it in December 2024 and received a bug bounty reward of $10,000 (roughly Rs. 8.5 lakh). Meta spokesperson Ryan Daniels told the publication that the issue was fixed in January, and that the company did not find any evidence of the method being used by bad actors.

The vulnerability reportedly was in how Meta AI handled user prompts on its servers. The researcher told the publication that the AI chatbot assigns a unique ID to every prompt and its AI-generated responses whenever a logged-in user tries to edit the prompt to regenerate an image or text. In a general use case, such incidents are very common, as most people conversationally try to get a better response or a desired image.

Advertisement

Hodkasia reportedly found that he could access his unique number by analysing the network traffic on the browser while editing an AI prompt. Then, by changing the number, the researcher could access someone else's prompt and designated AI response, the report claimed. The researcher claimed that these numbers were “easily guessable” and finding another legitimate ID did not take much effort.

Advertisement

Essentially, the vulnerability existed in the way the AI system handled the authorisation of these unique IDs, and did not place enough security measures to check who was accessing this data. That means, in the hands of a bad actor, this method could have led to compromising a large amount of private data of users.

Notably, a report last month found that the Meta AI app's discover feed was filled with posts that appeared to be private conversations with the chatbot. These messages included asking for medical and legal advice, and even confessing to crimes. Later in June, the company began showing a warning message to dissuade people from unknowingly sharing their conversations.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Galaxy S25 FE Launched With Exynos 2400 SoC: See Price
  2. Amazon Great Indian Festival 2025 Sale Will Begin on This Date
  3. Tecno Pova Slim 5G India Launch Today: All You Need to Know
  4. Tecno Pova Slim 5G Launched in India With 5.95mm Thin Profile: See Price
  5. Samsung Launches Galaxy Tab S11 Series With Galaxy AI, These Features
  6. Redmi 15C 4G Launched in Select Global Markets With These Features
  7. Lava Yuva Smart 2 Debuts in India: Know The Price, Specifications
  8. Apple Said to Plan a Perplexity-Like AI Web Search Tool for Siri
  9. IFA 2025: Acer Launches New Predator Helios, Orion, Nitro Series Laptops
  1. Tecno Pova Slim 5G Launched in India With 5.95mm Thin Profile, 6.78-Inch AMOLED Screen: Price, Features
  2. Amazon Great Indian Festival Sale 2025 Date Announced; Deals on Smartphones, Laptops From Samsung, Dell, Asus, and More Teased
  3. PS5 Digital Edition is Reportedly Getting Reduced SSD Storage in Europe
  4. Samsung Galaxy Tab S11, Galaxy Tab S11 Ultra Launched With Dimensity 9400 SoC, Up to 14.6-Inch Displays
  5. Samsung Galaxy S25 FE Launched With Exynos 2400 SoC, 50-Megapixel Rear Camera: Price, Specifications
  6. Lava Yuva Smart 2 Debuts in India With a 5,000mAh Battery, 3GB RAM: Price, Specifications
  7. Ethereum Builds Momentum as Bitcoin Price Consolidates Above $110,000
  8. Apple Reportedly Plans AI Web Search Tool for Siri, Using Google’s AI Model for Responses
  9. Garmin Fenix 8 Pro Launched in AMOLED and MicroLED Variants With LTE, Satellite Connectivity
  10. Vivo X300 Pro Certification Indicates It Might Offer the Same Charging Speed as the Vivo X200 Pro
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.