Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
China-Linked Showboat Malware Targets Telecom via Linux
June 19, 2026
Node.js Fixes 12 Vulnerabilities, Including 2 High-Severity
June 19, 2026
CISA Warns: Splunk Enterprise Critical Fl Function Vulnerability
June 19, 2026
Home/CyberSecurity News/Instagram Fixes Flaw Exposing User Emails Password Reset
CyberSecurity News

Instagram Fixes Flaw Exposing User Emails Password Reset

A critical logic bug within Instagram’s web-based password reset flow, first reported on June 6, 2026 Instagram’s parent company Meta deployed an emergency hotfix within hours of the disclosure, but...

Emy Elsamnoudy
Emy Elsamnoudy
June 7, 2026 3 Min Read
34 0

A critical logic bug within Instagram’s web-based password reset flow, first reported on June 6, 2026

Instagram’s parent company Meta deployed an emergency hotfix within hours of the disclosure, but not before proof-of-concept screenshots circulated widely on social media, demonstrating the scope of the vulnerability.

The vulnerability resided in Instagram’s web-based password reset interface, where the account recovery screen, designed to display only partially redacted recovery options, failed to properly mask sensitive contact data before presenting it to the requesting party.

Researchers discovered that by initiating a standard password reset for any given username, the response returned fully visible email addresses and phone numbers rather than the partially obscured versions Instagram normally shows (e.g., m***@fb.com).

Proof-of-concept screenshots shared by security community accounts, including @vxunderground, showed login screens for accounts such as zuck revealing multiple associated emails alongside a linked phone number. This constitutes a direct violation of Meta’s data minimization policies and potentially GDPR Article 25 obligations around privacy by design.

Meta is still having some minor security problems. Instagram is currently exposing phone numbers and email addresses associated with accounts when trying to perform a password reset

This is cool and badass because everyone is sharing Mark Zuckerbergs phone number right now

— vx-underground (@vxunderground) June 6, 2026

The bug was first spotted and publicly demonstrated on June 6, 2026, by security researchers monitoring Meta’s account recovery infrastructure.

Within hours of the demonstrations going viral, security researcher @Scot0xo confirmed on X that the flaw was a logic bug in the web reset flow, not an API credential leak or server-side breach that leaked sensitive account data before Meta responded with a targeted emergency hotfix.

Meta is moving from one security failure to another. A few hours ago, a new logic bug dropped in the Web Reset flow, leaking sensitive account data before getting hit with an emergency hotfix. This is what happens when you fire the experts and rely on brain-dead AI to run core… pic.twitter.com/qbjEhVjUQi

— Scot (@Scot0xo) June 6, 2026

Meta confirmed the patch was applied rapidly, echoing its standard response posture: “We fixed an issue that allowed an external party to request password reset emails for some Instagram users. There was no breach of our systems.”

This incident is the latest in a string of Instagram security issues in 2026. In January, a similar password reset abuse allowed third parties to trigger reset emails en masse, coinciding with the alleged leak of 17.5 million Instagram user records on dark web forums.

In early June, a separate vulnerability in Meta’s AI-powered support chatbot was exploited by threat actors who used prompt injection to hijack high-profile accounts, including the White House archive page and U.S. Space Force accounts, by convincing the bot to link target accounts to attacker-controlled email addresses.

Security researchers have attributed the increasing frequency of these failures partly to architectural decisions around AI-driven automation of sensitive account functions, noting that granting AI systems privileged access to account recovery without robust identity verification creates systemic risk.

Meta confirmed that no widespread data exfiltration occurred in the June 6 incident. However, even brief exposure of unredacted account recovery data creates meaningful risk for phishing, SIM-swapping, and targeted account takeover attacks. The enumeration of multiple email addresses tied to a single account could also help adversaries map identity infrastructure across services.

Meta has not disclosed a CVE identifier for this logic flaw as of publication time. Users and security teams should continue monitoring Meta’s security advisories for further disclosure details.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachCVEExploitPatchphishingSecurityThreatVulnerability

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

CISA Warns: Linux Kernel Auth Fl Improper Authentication

Next Post

EDRChoker Tool Blocks EDR Processes Uses Policy-Based

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Authorities Seize SocGholish Malware Network: Dismantle Servers
June 18, 2026
iPhone BootROM Vulnerability: Apple SoCs Face Exposes Full
June 18, 2026
Hackers Steal Salesforce CRM Data via Klue Breached Integration
June 18, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us