HeadlinesBriefing favicon HeadlinesBriefing.com

Instagram AI Security Flaw Exposes High-Profile Accounts

9to5Mac •
×

Hackers exploited a critical flaw in Meta's AI-powered support system to gain control of high-profile Instagram accounts. The attack method was surprisingly simple: attackers initiated a password reset, selected Meta AI Support Assistant, requested the chatbot add a new email address, and used the verification code to take over accounts. This logged out legitimate owners from all devices.

Victims included the Obama-era White House Instagram account, the U.S. Space Force's chief master sergeant John Bentivegna, and security researcher Jane Wong. The vulnerability allowed attackers to bypass security measures on accounts without multi-factor authentication, raising serious questions about AI safety in customer support systems.

Meta has since patched the vulnerability and is rolling out new protections for teenage users. These measures limit exposure to potentially harmful content on Instagram's Feed, Explore, and Reels. The company recognizes that content about topics like nutrition and anxiety can be helpful but shouldn't dominate a teen's experience, implementing balanced content algorithms to protect young users.