Researcher bags £8k reward for finding Facebook album delete flaw
Security researcher discovered whole photo albums could be deleted from Facebook by outsiders via the Graph API


A Facebook security flaw that could have paved the way for hackers to delete users' photo albums has won the researcher who discovered it an 8,000 bounty.
Lakshman Muthiyah, a researcher based in Tamil Nadu, said he was experimenting with the Facebook Graph API that allows developers to read and write data in Facebook applications, when he discovered he could send a "delete" function to a Facebook for Mobile application using the API that allowed him to delete any photo album on the site.
"This post is about a vulnerability found by me which allows a malicious user to delete any photo album on Facebook. Any photo album owned by an user or a page or a group could be deleted," Muthiyah said, in a blog post.
"I immediately reported this bug to the Facebook security team. They were too fast in identifying this issue and there was a fix in place in less than two hours from the acknowledgement of the report."
Facebook said in a statement: "We received a report about an issue with our Graph API and quickly fixed it."
The majority of Facebook bugs are uncovered by Indian security researchers, while the UK, Turkey and Germany come next in the charts. The company has been known to pay bounties up to 13,000 and to date, it has paid out over 1m to more than 300 researchers.
At the beginning of the month, Google announced it would be launching the Vulnerability Research Grants scheme, offering enhanced bounties for security researchers uncovering bugs on all its platforms, including within Google-developed Android apps.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Google security engineer Eduardo Vela Nava said on the company's blog: "We'll publish different types of vulnerabilities, products and services for which we want to support research beyond our normal vulnerability rewards.
"We'll award grants immediately before research begins, with no strings attached. Researchers then pursue the research they applied for, as usual. There will be various tiers of grants, with a maximum of $3,133.70."

Clare is the founder of Blue Cactus Digital, a digital marketing company that helps ethical and sustainability-focused businesses grow their customer base.
Prior to becoming a marketer, Clare was a journalist, working at a range of mobile device-focused outlets including Know Your Mobile before moving into freelance life.
As a freelance writer, she drew on her expertise in mobility to write features and guides for ITPro, as well as regularly writing news stories on a wide range of topics.
-
Cleo attack victim list grows as Hertz confirms customer data stolen
News Hertz has confirmed it suffered a data breach as a result of the Cleo zero-day vulnerability in late 2024, with the car rental giant warning that customer data was stolen.
By Ross Kelly
-
Lateral moves in tech: Why leaders should support employee mobility
In-depth Encouraging staff to switch roles can have long-term benefits for skills in the tech sector
By Keri Allan
-
Meta to pay $725 million in Cambridge Analytica lawsuit settlement
News The settlement closes the long-running lawsuit into how Facebook's owner, Meta, handled the Cambridge Analytica scandal
By Ross Kelly
-
Meta's earnings are 'cause for concern' and 2023 looks even bleaker
Analysis Calls for investor faith in metaverse tech only emphasise the worries that its investment strategy won't pay off
By Rory Bathgate
-
Microsoft and Meta announce integration deal between Teams and Workplace
News Features from both business collaboration platforms will be available to users without having to switch apps
By Connor Jones
-
Facebook is shutting down its controversial facial recognition system
News The move will see more than a billion facial templates removed from Facebook's records amid a push for more private applications of the technology
By Connor Jones
-
'Changing name to Meat': Industry reacts to Facebook's Meta rebrand
News The rebrand attempts to provide a clearer distinction between Facebook and its umbrella company
By Connor Jones
-
Facebook's Oversight Board demands more transparency
News Board bashed the social media giant for its preferential treatment of certain high-profile accounts
By Danny Bradbury
-
Facebook claims AI managed to reduce hate speech by 50%
News The social media platform has hit back at claims the tech it uses to fight hate speech is inadequate
By Sabina Weston
-
Facebook to hire 10,000 workers across the EU
News The high-skilled jobs drive is a “vote of confidence” in the European tech industry
By Jane McCallion