Security/ security · meta · instagram · ai

Instagram's AI Chatbot Bug Handed Account Resets to Hackers

A flaw in Meta AI's account-recovery flow let attackers redirect password-reset emails to themselves, exposing over 20,000 Instagram accounts.

Instagram's AI Chatbot Bug Handed Account Resets to Hackers

A bug in Instagram's Meta AI chatbot let attackers redirect account-recovery emails to an address they controlled.

Meta confirmed the flaw affected 20,225 users. The vulnerability lived inside the account-recovery flow, where Meta AI fields password-reset requests. Attackers could prompt the chatbot to send a reset link to their own email rather than the legitimate account holder's — a classic account-takeover technique dressed up in an AI interface. Meta has since patched it.

The precise figure — 20,225 — almost certainly wasn't offered out of goodwill. Formal data-breach notification rules in multiple jurisdictions require companies to report exact user counts to regulators, which means this crossed a legal disclosure threshold. The more durable issue is design: Meta AI is being handed privileges inside Instagram — triggering password resets, among them — that traditional security reviews were not built to evaluate. An AI with account-management authority is a bigger attack surface than a static web form, and the threat model is different enough that standard audits will keep missing it.

Meta keeps expanding what its AI assistant can do inside Instagram. Every new capability it gains is another thing that can be turned against the people using it.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →