Instagram 'Download Your Data' Tool Security Flaw Exposed Some Users' Passwords

Advertisement
By Tasneem Akolawala | Updated: 19 November 2018 18:38 IST
Highlights
  • Instagram has reported of a new bug in the data download tool
  • The tool mistakenly shared the user's password via a link
  • The bug has been fixed by Instagram

Instagram launched the data download tool in April this year

Instagram has reported to a few of its users that their password information may have been compromised due to a bug in the new 'Download Your Data' tool. Instagram has confirmed that the URL shared while using the tool included the user's password information as well, something that should not be the case. If this tool was used on a shared computer, this password information in the URL could potentially lead to misuse. The company notes that it has already fixed the bug, but recommends users to change their passwords nevertheless.

The 'download your data' feature was launched in April and it lets users export their photos, videos, archived Stories, profile, info, comments, and non-ephemeral messages. This tool gathers all your data, makes it ready for download, and then sends the user a link via email, clicking which will enable users to download all their Instagram data. Due to the security bug, the link also included the users' account password information erroneously, compromising the user's privacy. The Information reports that an Instagram spokesperson had confirmed that the issue was "discovered internally and affected a very small number of people."

Advertisement

While the link was shared to the user privately via email, if this link was accessed via a public or shared computer, it could risk the users' account credentials being compromised. Instagram says that it has already fixed the issue at hand. "If someone submitted their login information to use the Instagram 'Download Your Data' tool, they were able to see their password information in the URL of the page. This information was not exposed to anyone else, and we have made changes so this no longer happens," and Instagram spokesperson told The Verge.

Even though the issue is fixed, a security researcher cited by The Information brings to light a larger issue with the bug, saying it would only have been possible if Instagram stored users' passwords in plain text format. The Instagram spokesperson disputed this claim saying that the company hashes and salts its stored passwords. While Instagram says that the issue has affected a very small number of people, we recommend that you change your password immediately, and use the data download tool with caution.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Instagram
Advertisement

Related Stories

Popular Mobile Brands
  1. Xiaomi TV S Mini LED 75 (2026) Review
  2. Poco M8s 5G Debuts Globally With 7,000mAh Battery: See Price, Features
  3. Oppo Find X9 Ultra With 200-Megapixel Periscope Camera Launched Globally
  4. Microsoft Cuts Xbox Game Pass Prices in India, Global Markets
  5. OnePlus Ace 6 Ultra's Key Specifications Surface via Geekbench Listing
  6. These Vivo Smartphones Will Cost More in India Due to the Latest Price Hike
  7. Motorola Edge 70 Pro+ Leaked Renders Hint at Design, Five Colour Options
  8. GeForce Now Review:  Is Nvidia's High-End Cloud Gaming Service For You?
  9. Vivo Y6t Launched With 6,500mAh Battery, Snapdragon 4 Gen 2 SoC
  10. Vivo X300 FE Roundup: Expected Price in India, Specifications
  1. Spotify Ads Manager Platform Launched in India, Brings Self-Serve Advertising to Businesses
  2. Microsoft Cuts Xbox Game Pass Prices in India, Global Markets; Ends Day-One Call of Duty Access
  3. Incoming Apple CEO John Ternus Already Driving AI Overhaul Ahead of Leadership Transition: Report
  4. NASA Shuts Down Voyager 1 Instrument to Extend Mission Life in Deep Space
  5. Oppo Enco Clip 2 With Open-Ear Design, Up to 40 Hours Total Battery Life Launched Alongside Oppo Watch X3 Mini
  6. Vivo Y6t Launched With 6,500mAh Battery, Snapdragon 4 Gen 2 SoC: Price, Specifications
  7. OCBC Partners Lion Global Investors and DigiFT to Launch Tokenised Gold Fund With GOLDX Token
  8. Oppo Pad 5 Pro Launched With 13,380mAh Battery, Snapdragon 8 Elite Gen 5 SoC Alongside Oppo Pad Mini: Price, Features
  9. Redmi K90 Max Launched With Dimensity 9500 SoC, 8,550mAh Battery and Active Cooling Fan: Price, Specifications
  10. Oppo Find X9 Ultra Launched With Snapdragon 8 Elite Gen 5 SoC, 200-Megapixel Periscope Camera: Price, Specifications
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.