Indian engineer gets $12,500 bounty for finding a Facebook bug that let anyone delete pictures

Advertisement
By Anupam Saxena | Updated: 3 September 2013 13:55 IST
Facebook had a security bug that could be exploited to delete any image on the social networking site posted by anyone, without the original poster's knowledge and approval.

Interestingly, an Indian electronics and communications engineer, Arul Kumar, discovered this vulnerability and shared it with Facebook under its Whitehat bug reporting program, winning a $12,500 bounty in the process.

The 21-year old engineer from Tamil Nadu, discovered that the mobile version of Facebook's Support Dashboard, which allows users to flag and report a picture for removal, could be exploited to remove any photograph posted by any Facebook user.

When a user sends a photo removal request through the Support Dashboard, usually Facebook takes a look and decides if it should be removed or not. If Facebook decides not to remove it, then the user has the option of sending a message to the user who has posted the picture with a request to remove the same picture. The request also contains a link, clicking on which leads to the removal of the photo.

Advertisement

Kumar discovered that while sending a removal request, a user can manually modify the Photo_id and the photo owner's Profile_id parameters, following which the photo removal link can be sent to one's own Facebook ID and used to delete the photo without the original uploader's knowledge. Using the same method, any picture on Facebook could be deleted without the involvement of the user who originally posted the picture.

Advertisement

As per Kumar, the same exploit could have been used for removing photos posted by even verified users, fan pages and groups and from status updates, photo albums, suggested posts and comments.

When Kumar first shared the vulnerability with Facebook, it was dismissed, with the Facebook security team unable to delete any pictures through the suggested hack. Following this, Kumar sent Facebook a proof of concept video demonstrating the bug through a dummy account. The second attempt was fruitful and the Facebook security team was able to see the vulnerability.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Arul Kumar, Facebook, Facebook bug
Advertisement
Popular Mobile Brands
  1. Samsung Galaxy S26+ Reportedly Listed for Sale Online Ahead of Launch
  2. Vivo X300 FE Reportedly Bags IMDA and TUV Certifications Ahead of Launch
  3. Deals on iPhone 17, Google Pixel 10 and More During Flipkart Sale
  4. Poco X8 Pro Spotted on Geekbench With This Dimensity 8000 Series Chipset
  5. Xiaomi 17 Series Leak Hints at Imminent Launch Ahead of MWC at These Prices
  6. Samsung Galaxy A27 5G Lands on IMEI Database, Could Launch Soon
  7. Tecno Spark 50 4G Launch Timeline, Design, Colourways, Key Features Leaked
  8. Anthropic's First Indian Office in Bengaluru Is Now Open
  9. Oppo K14x 5G With 6,500mAh Battery Goes on Sale in India: See Price, Offers
  1. Sony Could Reportedly Delay PS6 to as Late as 2029 Due to RAM Shortage
  2. iPhone 18 Series to Drop SIM Card Slot in Europe to Make Room for Slightly Larger Battery: Report
  3. Poco X8 Pro Spotted on Geekbench With MediaTek Dimensity 8500 Ultra SoC, Android 16
  4. Xiaomi 17, Xiaomi 17 Ultra Global Price Details, Launch Date and Colour Options Leaked
  5. X Building Smart 'Cashtags' to Let Users Check Cryptocurrency Prices in Real-Time
  6. Samsung Galaxy A27 5G Listing on IMEI Database Suggests a Galaxy A26 Successor Is on the Way
  7. Anthropic Inaugurates First Indian Office in Bengaluru, Starts Hiring Local Talent
  8. Apple Tipped to Adopt Samsung's Privacy Display Technology for MacBook Models by 2029
  9. Oppo Find X10 Series Tipped to Launch in H2 2026 With Built-In Magnets for Wireless Charging
  10. AMD and TCS to Co-Develop Helios AI Data Centre Architecture, Deliver 200MW Data Centre Blueprint
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.