Facebook Fixes Bug That Could Have Deleted Any Public Photo

Advertisement
By Hitesh Arora | Updated: 13 February 2015 12:55 IST
We probably had never clicked so many pictures, if there was no Facebook. Uploading those pictures to your Facebook profile (even if privately) means a sense of safe storage for most people, which can be downloaded any time again. But, what if you go back and see no pictures there?

On Thursday, a software engineer Laxman Muthiyah discovered a vulnerability which allowed anyone to delete any photo album by any user on Facebook.

"Any photo album owned by an user or a page or a group could be deleted," said Muthiyah, though he clarified later "photos which are public or the photos I could see," implying private photos as well if the attacker had permission to view the album. Security firm Sophos adds, "So long as [Muthiyah] had the photo album ID and permission to view the album he could delete it... Facebook album IDs are numeric, which means that guessing them is easy - you start with 1 and just keep going up. "

This was essentially a Graph API flaw in Facebook Android app which potentially allowed a target album to be deleted with its numbered ID. Facebook was quick to response on the reported vulnerability by Muthiyah and offered him $12,500 (approximately Rs. 7.76 lakhs) through Facebook's bug bounty program.

Advertisement

So how did that happen?

According to Muthiyah, while Facebook notes that its photo albums cannot be deleted using the album node in Graph API, he tried to delete one of his own photo albums with a Facebook for mobile access token using the same Graph API and it got deleted.

Advertisement

"I decided to try it with Facebook for mobile access token because we can see delete option for all photo albums in Facebook mobile application isn't it? Yeah and also it uses the same Graph API. so took a album id & Facebook for Android access token of mine and tried it," notes Muthiyah.

But when he tried the same for some other person's photo album with its album ID, it got deleted as well, "So, what's the next step? Took victim's album ID and tried to delete it. I was very curious to see the result. OMG the album got deleted!"

Advertisement

Luckily the bug has been fixed by Facebook, and Muthiyah played a true altruist by not trying to profit by it. Muthiyah said he "immediately reported this bug to Facebook security team." "They were too fast in identifying this issue and there was a fix in place in less than two hours from the acknowledgement of the report," he added.

Later, a Facebook representative also issued a statement on company's behalf, stating(via Sophos' Nakedsecurity blog), "We received a report about an issue with our Graph API and quickly fixed it within two hours of verifying the claims. To be clear, triggering this issue would have required knowledge of the ID of the target photo album, as well as permission to view the album based on the album's privacy settings. We'd like to thank the researcher who reported the issue to us through our bug bounty program."

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. ACT Fibernet Launches New Broadband Plans With Free OTT Subscriptions
  2. OnePlus 15R Surfaces on Benchmarking Site Ahead of India Launch
  3. Motorola Edge 70 With Pantone's 2026 Colour, Swarovski Crystals Launched
  4. Flipkart Buy Buy 2025 Sale: Nothing Phone 3, Phone 3a Deals Revealed
  5. Realme Watch 5 Launched in India With Up to 16-Day Battery Life: See Price
  6. Flipkart Buy Buy 2025 Sale With Discounts on iPhone 16 Begins on This Date
  7. Xiaomi May Launch This Tri-Fold Phone to Rival the Samsung Galaxy Z TriFold
  8. FaceTime, Snapchat Video Calls Have Reportedly Been Blocked in Russia
  9. Apple Announces App Store Awards 2025 Winners: Check List
  10. HMD 101, HMD 100 With Built-In Radio Launched in India at These Prices
  1. NotebookLM App Gets an In-Built Camera, Lets Users Upload Images as a Source
  2. HMD 101 Launched in India With 1,000mAh Battery, Auto Call Recording Alongside HMD 100: Price, Features
  3. Crypto Traders Await US Fed Signals as Bitcoin Price Drops to $91,900
  4. Nothing Phone 3a Lite Goes on Sale in India: See Price, Offers, Availability
  5. Realme Narzo Phones Confirmed to Launch in India Soon via Amazon
  6. Samsung Galaxy Watch Ultra 2 Launch Timeline Leaked; Could Debut Alongside Samsung Galaxy Watch 9
  7. Samsung Galaxy S26 Series May Get Exynos 2600 Chipset Exclusively in South Korea: Report
  8. Apple’s FaceTime Reportedly Blocked in Russia Alongside Snapchat’s Video Calling Feature
  9. Anthropic Releases New Claude Tool That Interviews Users About Their AI Usage
  10. ACT Fibernet Launches Revamped Broadband Plans Starting at Rs. 499
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.