Facebook scrambles to fix security hole exposing private pictures
A flaw in Facebook’s system for reporting objectionable photos on the website was exploited to view confidential images from its members’ accounts. The exploit has already been used to snatch photos from Facebook founder Mark Zuckerberg’s private photo collection which has been posted to Web.
The flaw, which was first revealed at a body-building website, allows a person to access some of a member’s photos, including private ones, by choosing to block or report the member for having an inappropriate profile picture. At the end of that process, Facebook will display photos from the member that are not ordinarily publicly available for viewing. If the member being reported is a “friend,” photos can not only be accessed, but enlarged to full scale.
In the posting at the body-building site, its author warns anyone inclined to try the exploit not to use their own Facebook account because it could get suspended. “I urge you to use [the exploit] on a dummy account if you care about keeping your Facebook profile active,” the poster advised.