A security researcher says he has received a significant bug bounty from Meta after discovering a critical vulnerability that exposed customer support data.
The vulnerability was discovered and reported to Meta in January 2026 by independent researcher Rony K Roy. The initial report to the social media giant described a security hole of limited severity, but further analysis revealed that the flaw’s impact was much higher than initially believed.
According to Roy, Meta rolled out patches in April and had not found any evidence of malicious exploitation.
The researcher disclosed his findings last week and told SecurityWeek that he received a $78,000 bug bounty from Meta.
Meta has not responded to SecurityWeek’s request to confirm Roy’s claims, but he is indeed listed as one of the top researchers on the company’s bug bounty leaderboard for 2026.
Read more...