This Is How I Could Have Reactivated Your Instagram Account Without Your Knowledge
In this write-up, I have shared the story of an Instagram bug where deactivated account could be sil 2026-4-29 05:5:43 Author: infosecwriteups.com(查看原文) 阅读量:10 收藏

In this write-up, I have shared the story of an Instagram bug where deactivated account could be silently reactivated without victim’s knowledge.

Shubham Bhamare

Press enter or click to view image in full size

Image created/designed by the author

✨ Non-members can read this write-up for free using this link.

Hi everyone, this is Shubham Bhamare. Today, I’m going to share the story of one of the most creative and painful findings of my bug hunting journey. The target? Instagram, which of course means Meta. 😅

This one is special, not because of the bounty (spoiler: there isn’t one 🥲), but because of everything around it. A last-minute hunt on New Year’s Eve just to keep a streak alive. A bug that could silently reactivate someone’s Instagram account without them ever touching their phone. A Meta security analyst who told me it would get a bounty. And then… well. You’ll see. 😅

Let’s get into it! 🚀

Long story short:

Let me set the scene before we get into the bug. 😄

I’ve been on the Meta Whitehat Hall of Fame for 4 consecutive years: 2018, 2019, 2020, and 2021.


文章来源: https://infosecwriteups.com/this-is-how-i-could-have-reactivated-your-instagram-account-without-your-knowledge-9d220bda5620?source=rss----7b722bfd1b8d--bug_bounty
如有侵权请联系:admin#unsafe.sh