Meta Bug Bounty: “Only Me” Workplace Disclosure
2018年发现的Facebook隐私漏洞:用户将工作单位设为“仅自己可见”后,朋友仍可通过联想建议功能间接获取该信息。此漏洞源于联想建议显示的朋友数量未正确隐藏。 2025-12-25 14:36:17 Author: infosecwriteups.com(查看原文) 阅读量:4 收藏

Gl1tch

Press enter or click to view image in full size

Hello everyone, today I want to share a bug I discovered back in 2018 while exploring Facebook’s privacy features. It was a subtle issue easy to miss but it had a meaningful privacy impact. This finding was eventually rewarded by Facebook after review, and I thought it would be useful for other researchers to understand how such small UI leaks can expose sensitive information.

🔍 Finding Summary

In 2018, I identified a privacy flaw in Facebook’s workplace section. Even when a user set their workplace visibility to “Only Me,” it was still possible for friends to indirectly discover that workplace through Facebook’s typeahead suggestions.

The issue came from the social context displayed in typeahead the small hint showing how many friends are associated with a workplace. Although the data was supposed to be hidden.

🛠️ Details

Facebook uses typeahead suggestions across the platform to help users quickly select companies, schools, and locations. These suggestions often include friend counts like:

“1 friend works here”

While testing, I noticed the following behavior:

  1. I added a workplace to my profile.

文章来源: https://infosecwriteups.com/meta-bug-bounty-only-me-workplace-disclosure-e80eda0c66bb?source=rss----7b722bfd1b8d--bug_bounty
如有侵权请联系:admin#unsafe.sh