The flaw, reported by an outside researcher through Meta's bug bounty program and not previously disclosed, could have allowed an attacker to access a user's dedicated virtual machine — an individualized cloud-based account containing data including emails and files, according to an internal Meta incident report reviewed by The Information.
Read full article