HeadlinesBriefing favicon HeadlinesBriefing.com

Meta’s AI chatbot flaw lets hackers hijack Instagram

Engadget •
×

Meta rolled out an AI‑powered support assistant in December, promising faster account recovery for locked Facebook and Instagram users. Security researchers now say the same chatbot let attackers hijack Instagram profiles, bypassing even two-factor authentication. Hackers simply instructed the bot to change the account’s email and trigger a password reset, as screenshots on Telegram demonstrate. The attack worked even when users had enabled recovery codes.

The vulnerability relied on the bot’s location‑verification logic, which accepted a VPN‑masked IP matching the target’s usual region. Meta patched the flaw after reports surfaced on X over the weekend, but the exact number of compromised accounts remains unknown. Discussions on Telegram trace the exploit back to March, suggesting weeks of exposure. By exploiting the location check, attackers avoided flagging by Meta’s fraud detection systems.

High‑profile takeovers, including a dormant Obama White House Instagram and accounts belonging to Sephora and a senior Space Force official, were linked to the same method. Meta’s communications VP Andy Stone confirmed the issue is resolved and that affected users are being secured. It also raises questions about relying on AI for support.