AI Briefing
KO

The latest Instagram "exploit" is the most ridiculous one I've seen

·2026.06.02 09:48

Key point

A vulnerability was discovered that allows account takeover using only a user's username, due to a lack of guardrails in Instagram's support AI.

Details

If an attacker obtains only the victim's username and VPN/proxy information for a nearby region, they can trick Meta's support AI into taking over the account.

When the attacker tells the AI that "the account has been hacked," the AI sends a verification code to any email address designated by the attacker. Here, the AI exposed a zero auth vulnerability, sending the code without additional verification of whether that email actually belonged to the existing owner.

Because this recovery flow is processed by the system as a 'reset by the genuine account owner,' existing 2FA (two-factor authentication) is completely bypassed. Additionally, no email or push notification is sent to the user at all during session revocation and password change, making it difficult to notice the damage immediately.

The core of the problem is that Meta, a $1.5 trillion company, had its support AI change the linked email based solely on a user's request, without proper guardrails. The vulnerability has already been patched, but it remained active for weeks to months, causing damage to high-profile accounts.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.