Jump to content

Instagram Vulnerability: Anyone Can Add You, See Your Photos.

Recommended Posts


Spanish security researcher Sebastián Guerrero has discovered a flaw in Instagram which he has dubbed the "Friendship Vulnerability." In short, it allows anyone to add themselves as a friend to your Instagram account. As a result, they can then view photos you have set to Private as well as profile information.

Guerrero blames the bug on Instagram's "lack of control on the logic applied to authorization feature." He explains that both the iPhone and Android apps are affected by the remote vulnerability. Furthermore, the security researcher notes that an attacker could attempt a brute force attack where he or she adds themselves as a friend to a list of users and then steals all their private albums.

In one example, Guerrero adds himself to Facebook co-founder and CEO Mark Zuckerberg's account (as you can see in the screenshot above). He then sends Zuckerberg a personal message of congratulation for buying Instagram:


Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.

  • Create New...