Instagram Patches Meta AI Support Assistant Hijacking Vulnerability

Published
Written by:
Lore Apostol
Lore Apostol
Cybersecurity Writer
Key Takeaways
  • Chatbot Vulnerability Exploited: Threat actors tricked the Meta AI Support Assistant into bypassing authentication protocols to hijack user profiles.
  • High-Profile Compromises: The breach affected prominent targets, including the Obama-era White House and U.S. Space Force personnel.
  • Vulnerability Remediation: Instagram patched the authentication flaw, neutralizing the exploit chain involving unauthorized email additions.

Instagram recently resolved a critical security vulnerability that enabled threat actors to hijack user accounts by exploiting Meta's AI-powered support infrastructure. Over the weekend, numerous individuals on Reddit and X reported unauthorized access to their profiles. The exploitation of this vulnerability impacted several prominent figures and organizations. 

Confirmed compromised accounts included the Instagram handle for the Obama-era White House, the official profile of U.S. Space Force chief master sergeant John Bentivegna, and the account of security researcher Jane Wong.

Authentication Bypass via Meta AI Support Assistant

The attack vector specifically relied on tricking the Meta AI Support Assistant into granting illicit access to the targeted accounts. A video circulating on X demonstrated the step-by-step technical process utilized by the threat actors. 

Meta AI Support Assistant vulnerability exploit | Source: André @oracles on X
Meta AI Support Assistant vulnerability exploit | Source: André @oracles on X

Attackers used a VPN to spoof the target's presumed geographical location, circumventing initial security tripwires. They then initiated a session with the Meta AI Support Assistant, instructing the bot to append a new email address to the target account. 

The chatbot subsequently sent a verification code to the hacker's email address. Upon sharing this verification code with the chatbot, the attacker gained access to the Reset Password button.

This way, the hacker gained a complete account takeover without ever compromising the legitimate email address linked to the victim's Instagram profile.

Incident Remediation

Following the public disclosure of the exploit, Instagram spokesperson Andy Stone confirmed that the underlying security issue was fixed, adding that the “claim about world leaders is totally false.”

Meta has not yet commented on the matter, and the total number of affected users is unknown.

Last month, Russian hackers targeted 13,500 Signal accounts in a hijacking campaign. In April,  a Milan court accepted a Meta Platforms class action over Facebook personal data scraping affecting 35 million users.


For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: