🚨 Instagram bug exposed private posts without login
A server-side authorization flaw in Instagram’s mobile web allowed anyone to view private account posts without authentication, following the account, or user consent. All that was needed was a username and a basic GET request with mobile headers.
The issue was disclosed by security researcher Jatin Banga after 102 days of coordinated disclosure. The bug returned HTML with embedded JSON that included CDN links to full-resolution private photos, captions, and metadata. It was not a caching issue, but a backend authorization failure.
Testing showed the bug affected around 28% of sampled private accounts, with the actual scope likely higher due to its conditional nature. That made it harder to detect and easier to abuse for targeted access.
Meta initially misclassified the report, later patched the behavior without acknowledgment, and officially claimed the issue could not be reproduced. No confirmation of a root cause or permanent fix was provided.
A reminder that privacy settings only matter if backend enforcement actually works.
✅ Follow @inst
Post #1657
28.3K

- ❤ 28
- 👍 4
- 💯 2
- 😱 1