Instagram AI support exploit allowed account takeovers
TL;DR. A flaw in Instagram's AI support system enabled attackers to reset passwords and bypass 2FA, leading to widespread account takeovers. - The exploit used location spoofing and an AI to send verification codes to attacker-controlled emails. - Instagram's AI accepted animated video selfies as identity proof, further simplifying the takeover. - Black markets quickly offered account takeover services before Meta patched the vulnerability. - The flaw bypassed existing security measures, including two-factor authentication.
- Instagram's AI support flow was exploited to reset account passwords.
- Bypassed 2FA and traditional recovery methods by treating the attacker as the true owner.
- Attackers used VPNs and AI-animated public photos to impersonate users.
- Black markets emerged, selling account takeover services due to the exploit.
- Meta has since patched the flaw, which was active for weeks or months.
Sources
- macrumors.com — macrumors.com
- The newest Instagram "exploit" is the goofiest I've seen — 0xsid.com
- techcrunch.com — techcrunch.com
- theverge.com — theverge.com
- krebsonsecurity.com — krebsonsecurity.com
- engadget.com — engadget.com
- theguardian.com — theguardian.com
- github.com — github.com