Facebook Fixes Bug That Could Have Deleted Any Public Photo

Advertisement
By Hitesh Arora | Updated: 13 February 2015 12:55 IST
We probably had never clicked so many pictures, if there was no Facebook. Uploading those pictures to your Facebook profile (even if privately) means a sense of safe storage for most people, which can be downloaded any time again. But, what if you go back and see no pictures there?

On Thursday, a software engineer Laxman Muthiyah discovered a vulnerability which allowed anyone to delete any photo album by any user on Facebook.

"Any photo album owned by an user or a page or a group could be deleted," said Muthiyah, though he clarified later "photos which are public or the photos I could see," implying private photos as well if the attacker had permission to view the album. Security firm Sophos adds, "So long as [Muthiyah] had the photo album ID and permission to view the album he could delete it... Facebook album IDs are numeric, which means that guessing them is easy - you start with 1 and just keep going up. "

This was essentially a Graph API flaw in Facebook Android app which potentially allowed a target album to be deleted with its numbered ID. Facebook was quick to response on the reported vulnerability by Muthiyah and offered him $12,500 (approximately Rs. 7.76 lakhs) through Facebook's bug bounty program.

Advertisement

So how did that happen?

According to Muthiyah, while Facebook notes that its photo albums cannot be deleted using the album node in Graph API, he tried to delete one of his own photo albums with a Facebook for mobile access token using the same Graph API and it got deleted.

Advertisement

"I decided to try it with Facebook for mobile access token because we can see delete option for all photo albums in Facebook mobile application isn't it? Yeah and also it uses the same Graph API. so took a album id & Facebook for Android access token of mine and tried it," notes Muthiyah.

But when he tried the same for some other person's photo album with its album ID, it got deleted as well, "So, what's the next step? Took victim's album ID and tried to delete it. I was very curious to see the result. OMG the album got deleted!"

Advertisement

Luckily the bug has been fixed by Facebook, and Muthiyah played a true altruist by not trying to profit by it. Muthiyah said he "immediately reported this bug to Facebook security team." "They were too fast in identifying this issue and there was a fix in place in less than two hours from the acknowledgement of the report," he added.

Later, a Facebook representative also issued a statement on company's behalf, stating(via Sophos' Nakedsecurity blog), "We received a report about an issue with our Graph API and quickly fixed it within two hours of verifying the claims. To be clear, triggering this issue would have required knowledge of the ID of the target photo album, as well as permission to view the album based on the album's privacy settings. We'd like to thank the researcher who reported the issue to us through our bug bounty program."

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Realme 15T With 50-Megapixel Selfie Camera Debuts in India: See Price
  2. Amazon Great Indian Festival Sale: Deals on Smartphones, Laptops Teased
  3. India's Indigenous Vikram Microprocessor Showcased at Semicon India 2025
  4. Realme 15T 5G India Launch Today: All You Need to Know
  5. Astronomers Propose Rectangular Telescope to Hunt Earth-Like Planets
  1. BCCI Says Crypto, Real Money Gaming Platforms Can’t Bid for Team India’s Title Sponsorship
  2. Scientists Discover Hidden Mantle Layer Beneath the Himalayas Challenging Century-Old Theory
  3. Astronomers Propose Rectangular Telescope to Hunt Earth-Like Planets
  4. Microsoft Testing Native Clipboard Sync Feature to Share Text Between Windows PCs, Android Devices
  5. Su From So OTT Release: When and Where to Watch This Kannada-Language Horror-Comedy Online
  6. Sennheiser Momentum 4 Wireless 80th Anniversary Edition Launched in India With Up to 60 Hour Battery Life
  7. Call of Duty Film Adaption Said to Be a 'Priority' at Paramount, Negotiations on to Acquire Rights
  8. Cannibal Solar Storm May Trigger Auroras as Powerful Geomagnetic Storm to Hit Earth Soon
  9. Apple's iPhone 8 Plus Listed as Vintage Product Ahead of iPhone 17 Launch, 11-Inch MacBook Air Now Obsolete
  10. Hidden Reason Behind Portugal’s Deadly Earthquakes Finally Explained
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.