{"id":18827,"date":"2018-11-13T14:27:00","date_gmt":"2018-11-13T14:27:00","guid":{"rendered":"http:\/\/c3bdb3d6-b7c6-4385-85ff-0ed6bde9e168"},"modified":"2018-11-13T14:27:00","modified_gmt":"2018-11-13T14:27:00","slug":"facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data\/","title":{"rendered":"Facebook patches another bug that could have allowed mass-harvesting of user data"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/zdnet4.cbsistatic.com\/hub\/i\/r\/2018\/11\/13\/8d94e325-52e0-4619-8bc2-783448db6510\/thumbnail\/770x578\/1379afddf037dfe434a29d31a7b7ca89\/imperva-facebook-bug.png\" class=\"ff-og-image-inserted\"\/><\/div>\n<p>Facebook engineers have plugged another bug in the social network&#8217;s underlying codebase that could have allowed a malicious threat actor to stealthily collect highly personal information about Facebook users.<\/p>\n<div class=\"relatedContent alignRight\">\n<h3 class=\"heading\"><span class=\"int\">More security news<\/span><\/h3>\n<\/div>\n<p>In an email exchange with ZDNet, Imperva&#8217;s Ron Masas, the security researcher who discovered the issue, says the bug resided in Facebook&#8217;s Search system.<\/p>\n<p>&#8220;I browsed Facebook&#8217;s online search results, and in their HTML noticed that each result contained an iframe element &#8212; probably used for Facebook&#8217;s own internal tracking,&#8221; Masas said.<\/p>\n<p>The researcher says that upon seeing this, he realized that by looking for an iframe inside the search results page he could determine if a search query has returned a positive or negative result.<\/p>\n<p>Using basic yes and no questions, Masas says he could infer if users have liked a particular page, if they&#8217;ve taken photos at certain geographical locations, if they had friends of a certain religion in their friends list, if they&#8217;ve shared posts with a specific text, if a user has friends with a particular name, if the user has friends living in a specific city or country, and many other highly sensitive details.<\/p>\n<p>These search queries, even if they didn&#8217;t expose fine-grained details, they did expose second-hand information that could reveal, when pieced together, the identity of a user and his friends circle.<\/p>\n<p>But access to some of this highly-personal information is only available to the user alone. An attacker wouldn&#8217;t be able to run these search queries via the public Facebook Search feature.<\/p>\n<section class=\"sharethrough-top\" data-component=\"medusaContentRecommendation\" data-medusa-content-recommendation-options=\"{&quot;promo&quot;:&quot;promo_ZD_recommendation_sharethrough_top_in_article_desktop&quot;,&quot;spot&quot;:&quot;dfp-in-article&quot;}\">\n<\/section>\n<p>To go around this limitation, Masas created a malicious web page on which an attacker could lure users. If the user interacts with this page in any way, such as scrolling or clicking, the page automatically executes malicious JavaScript code that automates these search queries in a new tab.<\/p>\n<p>Masas told ZDNet that an attacker could use a technique called &#8220;tab under&#8221; to force the opening of the Facebook Search page inside a background tab, which keeps the user&#8217;s focus on the main malicious page &#8211;which could be disguised as an online game, movie streaming portal, or news article.<\/p>\n<p>Since the tab under technique is regularly used nowadays for pushing intrusive online ads, most users wouldn&#8217;t even pay attention to the new tab being opened in their browser&#8217;s background, considering just another ad.<\/p>\n<p>While the user is interacting with the malicious page, Masas&#8217; script would automate a series of Facebook searches via the Facebook Graph API, count the number of iframes the search results returned via the &#8220;fb.frames.length&#8221; property, and log the results. The researcher shared a video of the attack &#8211;while it was still possible.<\/p>\n<p>The attack would surely not work if users have two-three tabs opened in their desktop browser and they see a new Facebook tab being opened, but since most users tend to keep a large number of tabs in the tab bar, there&#8217;s a high chance most users won&#8217;t even see the attack going on &#8211;especially if they&#8217;re focused on the attacker&#8217;s malicious page, which should be easy if the page delivers a game, news article, or video.<\/p>\n<p>Further, the attack is also very likely to be even more efficient on mobile devices, where tabs aren&#8217;t visible on screen, but only as a tab counter, which is often ignored.<\/p>\n<p>Masas told ZDNet that his attack worked against all browsers and was not limited to Chrome, like <a href=\"https:\/\/www.imperva.com\/blog\/a-bug-in-chrome-gives-bad-actors-license-to-play-20-questions-with-your-private-data\/\" target=\"_blank\" rel=\"noopener noreferrer\">a previous Facebook bug<\/a> he found in August.<\/p>\n<p>Furthermore, the attack also doesn&#8217;t need to open individual tabs for each search query, allowing the attacker to reload the existing tab with a new search URL at short intervals.<\/p>\n<p>In a blog post today, <a href=\"https:\/\/www.imperva.com\/blog\/facebook-privacy-bug\/\" target=\"_blank\" rel=\"noopener noreferrer\">Masas says<\/a> he reported the bug to Facebook in May this year, and the platform has rolled out fixes shortly after.<\/p>\n<p>The researcher&#8217;s findings shows that despite its expansive bug bounty program, Facebook will always have a hard time securing such a huge platform, and will always remain open to mass-harvesting operations, such as the <a href=\"https:\/\/www.zdnet.com\/article\/how-cambridge-analytica-used-your-facebook-data-to-help-elect-trump\/\" target=\"_blank\">Cambridge Analytica scandal<\/a> or the <a href=\"https:\/\/www.zdnet.com\/article\/facebook-downgrades-breach-count-from-50-million-to-30-million-users\/\" target=\"_blank\">recent security breach<\/a> caused by another platform feature &#8212;<a href=\"https:\/\/www.zdnet.com\/article\/facebook-says-it-detected-security-breach-after-traffic-spike\/\" target=\"_blank\">the View As button<\/a>.<\/p>\n<h3>Related cyber-security coverage:<\/h3>\n<p>READ MORE <a href=\"https:\/\/www.zdnet.com\/article\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data\/#ftag=RSSbaffb68\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Imperva security researcher publicly discloses bug today, but Facebook patched the issue back in May.<br \/>\nREAD MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":18828,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[62],"tags":[],"class_list":["post-18827","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-zdnet-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Facebook patches another bug that could have allowed mass-harvesting of user data 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Facebook patches another bug that could have allowed mass-harvesting of user data 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2018-11-13T14:27:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/11\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data.png\" \/>\n\t<meta property=\"og:image:width\" content=\"770\" \/>\n\t<meta property=\"og:image:height\" content=\"578\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Facebook patches another bug that could have allowed mass-harvesting of user data\",\"datePublished\":\"2018-11-13T14:27:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data\\\/\"},\"wordCount\":717,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/11\\\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data.png\",\"articleSection\":[\"ZDNet | Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data\\\/\",\"name\":\"Facebook patches another bug that could have allowed mass-harvesting of user data 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/11\\\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data.png\",\"datePublished\":\"2018-11-13T14:27:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/11\\\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/11\\\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data.png\",\"width\":770,\"height\":578},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Facebook patches another bug that could have allowed mass-harvesting of user data\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Facebook patches another bug that could have allowed mass-harvesting of user data 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data\/","og_locale":"en_US","og_type":"article","og_title":"Facebook patches another bug that could have allowed mass-harvesting of user data 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2018-11-13T14:27:00+00:00","og_image":[{"width":770,"height":578,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/11\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data.png","type":"image\/png"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Facebook patches another bug that could have allowed mass-harvesting of user data","datePublished":"2018-11-13T14:27:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data\/"},"wordCount":717,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/11\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data.png","articleSection":["ZDNet | Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data\/","url":"https:\/\/www.threatshub.org\/blog\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data\/","name":"Facebook patches another bug that could have allowed mass-harvesting of user data 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/11\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data.png","datePublished":"2018-11-13T14:27:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/11\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/11\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data.png","width":770,"height":578},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/facebook-patches-another-bug-that-could-have-allowed-mass-harvesting-of-user-data\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Facebook patches another bug that could have allowed mass-harvesting of user data"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/18827","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=18827"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/18827\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/18828"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=18827"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=18827"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=18827"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}