GoPlus: Meta account recovery feature exposed to high-risk design flaws, which could directly leak users' sensitive information
GoPlus posted on platform X that the Meta account recovery feature has been exposed to a high-risk design flaw, which could directly leak users' phone numbers, email addresses, and PII (Personally Identifiable Information). Attackers only need to input the META username without any login or verification to directly obtain the complete PII linked to the user, such as email addresses and phone numbers. This could pose significant risks to users, including: large-scale phishing attacks, SIM card swapping attacks, account takeover and identity theft, and targeted social engineering attacks.
Recommendations: Remove or change the leaked email/phone number as a recovery method; modify related account passwords and enable 2FA; do not click on any emails or messages related to "account anomalies," "verification," or "password reset"; set up multi-channel verification, which can be verified through official documents or other official social media channels.
You may also like

The other side of Musk's trillion-dollar fortune: 85% cannot be sold

The U.S. government prohibits foreigners from using Fable 5, Anthropic issues a rebuttal

Citibank releases "2030 Asset Tokenization Market Outlook": 6 major trends may create a $8.2 trillion market

The trillion-dollar valuation test: Are the three major super IPOs a celebration for tech stocks or a nightmare for the crypto market?

Morning Report | Digital Asset completes $355 million financing led by a16z Crypto; Meta completes operational separation from Manus

a16z Crypto Partner: Cash flow is the moat

Cryptocurrency market makers collectively seek change as it becomes increasingly difficult to make money

How TradeXYZ, xStocks, and Alpaca break down the SpaceX IPO into three different strategies

$75 billion in risk asset redistribution: How will SpaceX's IPO affect U.S. stocks and Bitcoin?

Why Is BlackRock Investing $5 Billion in the SpaceX IPO?

Morning News | CME Group launches Nasdaq Cryptocurrency Index futures; Asset management giant Janus Henderson strategically invests in Ethena

Bitcoin Layer 2 Network Botanix: Why Did We Choose to Dissolve?

Why did Oracle deliver the strongest financial report in history, yet its stock price fell?

When the P2P illicit funds from ten years ago turned into 60,000 bitcoins

Dialogue with OmenX Founder: Why does the prediction market need an evolution from "spot" to "derivatives"?

Galaxy in-depth report: Is Solana still worth paying attention to?

Young people in South Korea make a "final effort" in the epic bull market




