Indian engineer gets $12,500 bounty for finding a Facebook bug that let anyone delete pictures

Advertisement
By Anupam Saxena | Updated: 3 September 2013 13:55 IST
Facebook had a security bug that could be exploited to delete any image on the social networking site posted by anyone, without the original poster's knowledge and approval.

Interestingly, an Indian electronics and communications engineer, Arul Kumar, discovered this vulnerability and shared it with Facebook under its Whitehat bug reporting program, winning a $12,500 bounty in the process.

The 21-year old engineer from Tamil Nadu, discovered that the mobile version of Facebook's Support Dashboard, which allows users to flag and report a picture for removal, could be exploited to remove any photograph posted by any Facebook user.

When a user sends a photo removal request through the Support Dashboard, usually Facebook takes a look and decides if it should be removed or not. If Facebook decides not to remove it, then the user has the option of sending a message to the user who has posted the picture with a request to remove the same picture. The request also contains a link, clicking on which leads to the removal of the photo.

Advertisement

Kumar discovered that while sending a removal request, a user can manually modify the Photo_id and the photo owner's Profile_id parameters, following which the photo removal link can be sent to one's own Facebook ID and used to delete the photo without the original uploader's knowledge. Using the same method, any picture on Facebook could be deleted without the involvement of the user who originally posted the picture.

Advertisement

As per Kumar, the same exploit could have been used for removing photos posted by even verified users, fan pages and groups and from status updates, photo albums, suggested posts and comments.

When Kumar first shared the vulnerability with Facebook, it was dismissed, with the Facebook security team unable to delete any pictures through the suggested hack. Following this, Kumar sent Facebook a proof of concept video demonstrating the bug through a dummy account. The second attempt was fruitful and the Facebook security team was able to see the vulnerability.
 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Arul Kumar, Facebook, Facebook bug
Advertisement
Popular Mobile Brands
  1. Vivo Y31 Series With 6,500mAh Battery Launched in India: See Price
  2. Samsung Begins Rolling Out One UI 8 Update to the Galaxy S25 Series
  3. Flipkart Big Billion Days Sale: Discounts on Motorola Phones Announced
  4. iOS 26 Update Brings These New Features to AirPods Pro 3, Pro 2, AirPods 4
  5. Samsung Galaxy S25 FE With 50-Megapixel Camera Launched in India: See Price
  6. Check What's New for Your iPhone in Apple's Latest iOS 26 Update
  7. Vivo V60e 5G Design, Price Leaked; May Use Same Chip as Vivo V50e
  8. iQOO 15 Live Image Leaked; Company Reveals Display Details
  9. Oppo F31 Pro+ 5G Review
  10. GTA 6 Will Be the 'Largest Game Launch in History', Says Rockstar Games
  1. Clair Obscur: Expedition 33 Has Sold 4.4 Million Copies in Less Than Six Months of Launch
  2. Materialists Now Streaming on Netflix: What You Need to Know About Dakota Johnson’s Starrer Movie
  3. The Trial Season 2 OTT Release Date: When and Where to Watch Kajol’s Legal Drama Series Online
  4. Ghaati OTT Release Reportedly Revealed Online: When and Where to Watch Anushka Shetty-Starrer Movie Online?
  5. American Express Launches NFT Passport Stamps to Commemorate Travel Memories
  6. Huawei Watch GT 6, GT 6 Pro Price, Specifications Leak Ahead of September 19 Launch: Report
  7. iPhone 17 Pro Max in Cosmic Orange Colourway Reportedly Out of Stock in the US, India
  8. Samsung Galaxy Tab A11, Galaxy Tab A11+ Leaked Renders Hint at Design, Specifications
  9. Apple Adds New and Upgraded Apple Intelligence Features for iPhone, iPad and Mac Devices
  10. MediaTek Dimensity 9500 Launch Date Announced; Company Designs Its First Chip Using TSMC’s 2nm Process
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.