A security researcher says Meta paid him a $78,000 bug bounty after he found a critical flaw that exposed customer support data tied to Meta’s backend support infrastructure and Meta Horizon Managed Solutions. The issue involved missing authorization, broken access control, and IDOR bugs that could have revealed support conversations, case details, and personal information. #Meta #MetaHorizonManagedSolutions #RonyKRoy
Keypoints
- Rony K Roy reported the flaw to Meta in January 2026.
- The issue was initially seen as limited but later proved much more serious.
- Meta patched the vulnerability in April and found no evidence of abuse.
- The bug affected Meta’s backend support infrastructure, not just Horizon Managed Solutions.
- An attacker could have accessed support cases, conversations, files, and personal data.