Meta Paid a Researcher $78,000 to Find a Flaw That Exposed Support Chats and Personal Data

An independent security researcher discovered a hole in Meta's internal support system that could have let anyone read private conversations between users and Meta support staff. Meta patched it quietly. Then came the cheque.

ThreatVectr Newsdesk· 3 min read
A close-up photorealistic view of a fractured dark blue computer chip on a black reflective surface, with hairline cracks glowing faint red from underneath, sha
Share

Key points

  • Researcher Rony K Roy reported a security flaw to Meta in January 2026 and received a $78,000 bug bounty payment.
  • The flaw sat inside Meta's backend support infrastructure and affected users of Meta Horizon Managed Solutions, an enterprise platform for managing Meta Quest headsets.
  • An attacker could have read private email and chat conversations between users and Meta support without any special permission.
  • Meta rolled out patches in April 2026 and found no evidence that anyone had exploited the flaw before it was fixed.
  • Roy appears on Meta's official bug bounty leaderboard for 2026, lending weight to his account, first reported by SecurityWeek.

A security researcher found a serious flaw buried in Meta's customer support system, reported it responsibly, and walked away with $78,000. The story behind that number is worth understanding.

Rony K Roy, an independent researcher, initially flagged what looked like a minor authorisation problem (a flaw controlling who is allowed to see what) inside Meta Horizon Managed Solutions in January 2026. That product lets businesses manage fleets of Meta Quest virtual-reality headsets. Routine stuff, on the surface.

Dig deeper, and the picture changed.

Further analysis revealed three overlapping weaknesses. Missing authorisation checks. Broken access controls. And something called an insecure direct object reference, or IDOR, where a system hands out internal file or record numbers in a predictable way, letting anyone who guesses the pattern pull up records they should never see.

Chained together, those three flaws reached well beyond Horizon Managed Solutions into Meta's broader support backend.

What could an attacker actually have done?

A lot, frankly. Someone exploiting this flaw could have read private email and live-chat conversations between ordinary users and Meta's support team. They could have downloaded files that users had attached to support tickets, seen personal contact details shared during those conversations, and listed open support cases by simply cycling through case numbers.

On top of reading data, an attacker could have taken action: filing fake support requests on behalf of companies, changing the status of existing cases, and adding themselves as a subscriber to cases they had no business seeing.

That last point matters. Support conversations often contain sensitive information, account details, billing queries, identity documents uploaded to prove ownership of a hacked account. Quietly subscribing to those conversations would give an attacker a steady feed of that material.

Meta patched the vulnerability in April 2026 and told Roy it had found no sign of malicious use. That is the best realistic outcome when a flaw like this surfaces through a legitimate bug bounty report rather than through criminal exploitation.

Would stronger multi-factor authentication (MFA, meaning a second proof of identity beyond a password) have helped here? Partly. But the core problem was that the system did not check permissions carefully enough in the first place. MFA stops uninvited people from logging in. It does not stop a logged-in user from wandering into rooms the system should have kept locked.

The $78,000 payout reflects how seriously Meta graded the potential damage. For ordinary Meta users who have ever contacted support, there is nothing to do right now. No data is confirmed stolen. Worth keeping an eye on your email for anything unexpected from Meta support, but the risk appears contained.

© 2026 Threat Vectr