Logo

Home Technology Cyber security Instagram Bug Briefly Exposed ...

Instagram Bug Briefly Exposed Private Posts to Strangers, Researcher Reveals


Cyber Security

Instagram Bug Briefly Exposed Private Posts to Strangers, Researcher Reveals

A quietly fixed flaw raised fresh concerns over privacy controls on one of the world’s biggest social platforms.

A newly disclosed security flaw in Instagram briefly allowed outsiders to view private photos and captions without logging in or following the account, according to a report released by cybersecurity researcher Jatin Banga. The issue, which affected Instagram’s mobile web interface, was quietly fixed by Meta late last year without a public announcement.

The vulnerability was not caused by a simple technical glitch, but by a deeper problem in how Instagram checked user permissions on its servers. By sending a specially crafted web request that mimicked a mobile browser, an unauthenticated user could target Instagram’s servers to return hidden data linked to private accounts.

In affected cases, the response included direct links to private images and their captions, hosted on Instagram’s content delivery network. Under normal conditions, this information should never be visible to anyone outside an approved follower list.

Testing showed the flaw did not impact every private account. Around one in four test accounts were vulnerable, suggesting the issue depended on a specific backend state rather than a universal error. That inconsistency has raised additional concern among security experts.

Banga reported the issue to Meta in October 2025 through its bug bounty program, providing technical evidence and a working proof of concept. Days later, the vulnerability stopped working, indicating it had been fixed. However, Meta later closed the report as “not applicable,” saying it could not reproduce the problem.

The lack of a clear explanation has drawn criticism from the security community. Banga has since released technical details publicly, warning that selective privacy leaks can be harder to detect and more dangerous than widespread flaws. The incident highlights ongoing challenges in securing user data at scale, even on mature platforms like Instagram.

Business News

Recommended News

Latest  Magazines