Explorer

Chennai Techie Finds Flaw In Instagram Again, Wins $10,000

The new vulnerability that Muthiyah spotted was similar to the one he reported in July and allowed anyone to hack Instagram accounts without consent permission.

Chennai: Barely a month after winning $30,000 from Facebook for spotting a flaw in Instagram, Chennai-based security researcher Laxman Muthiyah on Monday said he again discovered a new account takeover vulnerability on the photo and video-sharing app. This time he has won $10,000 as part of the social network's bug bounty programme. The new vulnerability that Muthiyah spotted was similar to the one he reported in July and allowed anyone to hack Instagram accounts without consent permission. Facebook has now fixed the vulnerability that Muthiyah reported. "Facebook and Instagram security team fixed the issue and rewarded me $10000 as a part of their bounty programme," Muthiyah said in a blog post. Muthiyah found that the same device ID - the unique identifier used by Instagram server to validate password reset codes - can be used to request multiple pass codes of different users. He showed that this vulnerability can be exploited to hack Instagram accounts. "You identified insufficient protections on a recovery endpoint, allowing an attacker to generate numerous valid nonces to ten attempt recovery," Facebook said in a letter to Muthiyah.

Top Headlines

Asus ProArt P16 And ProArt P14 Debut With RTX Spark AI Power At Computex 2026
Asus ProArt P16 And ProArt P14 Debut With RTX Spark AI Power At Computex 2026
iPhone 17 Price Slashed To Almost Half At 'Everything Apple' Sale: Here's How It Drops To Rs 44,768
iPhone 17 Price Slashed To Almost Half At 'Everything Apple' Sale: Here's How It Drops To Rs 44,768
iPhone 18 Pro Could Shoot Photos Like A DSLR: Here's What Apple Is Planning
iPhone 18 Pro Could Shoot Photos Like A DSLR: Here's What Apple Is Planning
iPhone Ultra Fold Video Leaked! Here Is Everything You Need To Know About The Rs 2 Lakh Phone
iPhone Ultra Fold Video Leaked! Here Is Everything You Need To Know About The Rs 2 Lakh Phone

Videos

Patna Security Alert: Heavy Police Deployment Outside Khan Sir Coaching Centre
Breaking News: US Airstrike Targets Iran’s Qeshm Island Military Infrastructure
Middle East Conflict: Iranian Missile Strike Targets U.S. Base in Kuwait
Breaking News: Huge Cash Recovery Inside Surendranath College Campus
Patna Update: Heavy Security Outside Khan Sir’s Coaching Centre After Attack

Photo Gallery

25°C
New Delhi
Rain: 100mm
Humidity: 97%
Wind: WNW 47km/h
See Today's Weather
powered by
Accu Weather
Embed widget