Meta Fixes Bug That Exposed Users' AI Data

Meta has resolved a security vulnerability that allowed its AI chatbot users to access and view the private prompts and generated responses of other users.
Sandeep Hodkasia, founder of the security testing firm AppSecure, exclusively informed TechCrunch that Meta awarded him a $10,000 bug bounty for privately reporting the issue, which he filed on December 26, 2024.
According to Hodkasia, Meta implemented a fix on January 24, 2025, and found no indication that the vulnerability had been exploited maliciously.
Hodkasia explained to TechCrunch that he discovered the bug while exploring how Meta AI lets logged-in users edit their prompts to regenerate text and images. He noticed that when a user edits a prompt, Meta's backend servers assign it and its AI-generated response a unique numeric identifier. By monitoring his browser's network traffic during an edit, Hodkasia found he could alter this identifier, causing the servers to return the prompt and response of a completely different user.
This flaw meant Meta's servers failed to properly verify whether a user was authorized to view a specific prompt and its response. Hodkasia stated the prompt identifiers generated by Meta's servers were "easily guessable," which could have allowed a malicious actor to scrape users' original prompts by rapidly cycling through numbers with automated tools.
When contacted by TechCrunch, Meta confirmed the fix was deployed in January. "We found no evidence of abuse and rewarded the researcher," Meta spokesperson Ryan Daniels stated.
This security issue emerges as major technology companies race to launch and improve their AI products, many of which carry significant security and privacy risks.
Meta AI's standalone app, introduced earlier this year to compete with rivals like ChatGPT, encountered a bumpy launch after some users accidentally shared conversations they believed were private.
Techcrunch event LIVE NOW! TechCrunch All Stage
Build smarter. Scale faster. Connect deeper. Join visionaries from Precursor Ventures, NEA, Index Ventures, Underscore VC, and beyond for a day packed with strategies, workshops, and meaningful connections.
Save $450 on your TechCrunch All Stage pass
Build smarter. Scale faster. Connect deeper. Join visionaries from Precursor Ventures, NEA, Index Ventures, Underscore VC, and beyond for a day packed with strategies, workshops, and meaningful connections.
Boston, MA | July 15 REGISTER NOW
Related article
Frontier AI Labs Refuse to Disclose Containment Strategies for Rogue Models
Recent research indicates that very few leading AI laboratories have published or demonstrated containment response plans. A containment plan defines the procedures for when an AI system attempts to subvert human control, specifying which access righ
Does Mark Zuckerberg Really Believe AI Is for Everyone?
Loading the player…Meta introduced Glimmer this week, an open-weight AI model that anyone can download and run on personal hardware—a sharp contrast to Muse Spark, the company’s more powerful model, which remains locked behind its own APIs. The relea
Facebook launches AI companion app for creators
Facebook revealed on Wednesday that it is transforming its Creator Studio into a dedicated AI companion app, empowering creators to expand their reach on the platform.By providing this AI-driven tool, Meta aims to retain creators on Facebook amid int
Related Special Topic Recommendations
Comments (1)
0/500
Krass, die Bug hatte ja richtig Potenzial für Drama 😅 Einerseits beeindruckend, wie schnell Meta das behoben hat, andererseits fragt man sich doch: Ist das nur die Spitze des Eisbergs? In jeder KI-Assistenten-Funktion stecken solche Datenschnittstellen versteckt. Das Problem ist ja nicht der Einzelfall, sondern dass immer wieder solche Lecks auftauchen. Als Nutzer bekommt man da langsam ein mulmiges Gefühl... Wäre vielleicht cool, wenn es transparente Protokolle gäbe, an denen unabhängige Sicherheitsforscher dauerhaft mitwirken könnten. So nach dem Motto: Vertrauen ist gut, Kontrolle ist besser 💡

Meta has resolved a security vulnerability that allowed its AI chatbot users to access and view the private prompts and generated responses of other users.
Sandeep Hodkasia, founder of the security testing firm AppSecure, exclusively informed TechCrunch that Meta awarded him a $10,000 bug bounty for privately reporting the issue, which he filed on December 26, 2024.
According to Hodkasia, Meta implemented a fix on January 24, 2025, and found no indication that the vulnerability had been exploited maliciously.
Hodkasia explained to TechCrunch that he discovered the bug while exploring how Meta AI lets logged-in users edit their prompts to regenerate text and images. He noticed that when a user edits a prompt, Meta's backend servers assign it and its AI-generated response a unique numeric identifier. By monitoring his browser's network traffic during an edit, Hodkasia found he could alter this identifier, causing the servers to return the prompt and response of a completely different user.
This flaw meant Meta's servers failed to properly verify whether a user was authorized to view a specific prompt and its response. Hodkasia stated the prompt identifiers generated by Meta's servers were "easily guessable," which could have allowed a malicious actor to scrape users' original prompts by rapidly cycling through numbers with automated tools.
When contacted by TechCrunch, Meta confirmed the fix was deployed in January. "We found no evidence of abuse and rewarded the researcher," Meta spokesperson Ryan Daniels stated.
This security issue emerges as major technology companies race to launch and improve their AI products, many of which carry significant security and privacy risks.
Meta AI's standalone app, introduced earlier this year to compete with rivals like ChatGPT, encountered a bumpy launch after some users accidentally shared conversations they believed were private.
Techcrunch eventLIVE NOW! TechCrunch All Stage
Build smarter. Scale faster. Connect deeper. Join visionaries from Precursor Ventures, NEA, Index Ventures, Underscore VC, and beyond for a day packed with strategies, workshops, and meaningful connections.
Save $450 on your TechCrunch All Stage pass
Build smarter. Scale faster. Connect deeper. Join visionaries from Precursor Ventures, NEA, Index Ventures, Underscore VC, and beyond for a day packed with strategies, workshops, and meaningful connections.
Boston, MA | July 15 REGISTER NOW
Frontier AI Labs Refuse to Disclose Containment Strategies for Rogue Models
Recent research indicates that very few leading AI laboratories have published or demonstrated containment response plans. A containment plan defines the procedures for when an AI system attempts to subvert human control, specifying which access righ
Does Mark Zuckerberg Really Believe AI Is for Everyone?
Loading the player…Meta introduced Glimmer this week, an open-weight AI model that anyone can download and run on personal hardware—a sharp contrast to Muse Spark, the company’s more powerful model, which remains locked behind its own APIs. The relea
Facebook launches AI companion app for creators
Facebook revealed on Wednesday that it is transforming its Creator Studio into a dedicated AI companion app, empowering creators to expand their reach on the platform.By providing this AI-driven tool, Meta aims to retain creators on Facebook amid int
Krass, die Bug hatte ja richtig Potenzial für Drama 😅 Einerseits beeindruckend, wie schnell Meta das behoben hat, andererseits fragt man sich doch: Ist das nur die Spitze des Eisbergs? In jeder KI-Assistenten-Funktion stecken solche Datenschnittstellen versteckt. Das Problem ist ja nicht der Einzelfall, sondern dass immer wieder solche Lecks auftauchen. Als Nutzer bekommt man da langsam ein mulmiges Gefühl... Wäre vielleicht cool, wenn es transparente Protokolle gäbe, an denen unabhängige Sicherheitsforscher dauerhaft mitwirken könnten. So nach dem Motto: Vertrauen ist gut, Kontrolle ist besser 💡





Home






