Meta has reportedly fixed a flaw in an AI-assisted Instagram account-recovery process that could allow attackers to direct password-reset verification to an email address they controlled, according to a breach notification and reporting by TechCrunch and BleepingComputer.
Meta fixed a security flaw in an AI-assisted Instagram support and account-recovery process after attackers could potentially obtain password-reset links for accounts they did not own, according to a breach notification cited by All About Security and reporting from TechCrunch and BleepingComputer.
The issue did not require attackers to breach Instagram's underlying systems, according to the available reports. Instead, it involved the handling of recovery requests through an AI-powered support path.
Meta's notification, published by All About Security, said a bug failed to confirm that a password-reset email address matched the email address already associated with the Instagram account. That failure could allow an unauthorized party to receive a reset link.
TechCrunch reported that it verified a case in which an attacker-controlled email inbox received a verification code after Meta's AI Support Assistant was prompted to add the address to a target account. The publication said Instagram confirmed that the issue had been fixed.
BleepingComputer similarly reported that attackers persuaded AI-powered support tooling to regard them as legitimate account owners. According to its report, this could result in associated email addresses being changed and enable an account takeover.
Account-recovery flows are a particularly sensitive part of social platforms' security systems because a successful reset can give an attacker control over a profile, its direct messages, and its connected services. The reported flaw illustrates that automated support systems need the same strict identity checks as conventional password-reset tools.
The reports describe an apparent weakness in how the recovery process validated a requested contact change, rather than a compromise of users' passwords through a conventional data breach. Users who suspect unauthorized changes to their account email address or password should use Instagram's official account-recovery and security settings, review logged-in devices, and enable two-factor authentication where available.
The breach notification referenced by All About Security describes the defect as a configuration or validation problem in the AI-assisted recovery route. TechCrunch said Instagram stated that it had resolved the problem.
The supplied reports do not establish how many accounts, if any, were affected. They also do not provide a complete public account of the period in which the flaw was exploitable. Meta's reported remediation is significant, but the incident raises broader questions about safeguards for AI-supported customer-service systems that can influence account ownership or credential recovery.
The issue did not require attackers to breach Instagram's underlying systems, according to the available reports.
Instead, it involved the handling of recovery requests through an AI powered support path.
Email verification failure Meta's notification, published by All About Security, said a bug failed to confirm that a password reset email address matched the email address already associated with the Instagram account.
Continue reading