Facebook flaw gave 5,000 developers access to users' data
Information from users' profiles was accessible after the 90-day time limit had expired

Facebook has admitted that it accidentally shared user data with developers for longer than it should have.
Facebook apps are supposed to prevent access to personal data if users have not used the app for more than 90 days. However, the social network has said that a flaw in how inactivity was recorded allowed approximately 5,000 developers to collect data from users’ profiles after the 90-day time limit on their rights had expired.
“Recently, we discovered that in some instances apps continued to receive the data that people had previously authorized, even if it appeared they hadn’t used the app in the last 90 days,” Facebook admitted in a statement.
“For example, this could happen if someone used a fitness app to invite their friends from their hometown to a workout, but we didn’t recognize that some of their friends had been inactive for many months.
“From the last several months of data we have available, we currently estimate this issue enabled approximately 5,000 developers to continue receiving information - for example, language or gender - beyond 90 days of inactivity as recognized by our systems.”
Facebook says it fixed the issue the day after discovering it, adding that it plans to investigate the slip-up and that it will continue to prioritize transparency with respect to any major updates. It has not stated how many users had their personal data scraped.
In 2018, the Cambridge Analytica privacy scandal exposed how third-party apps were harvesting Facebook users’ personal information. Cambridge Analytica’s app harvested the data of users who interacted with the app, as well as their friends who had not consented to the use of their data.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Following the US Congress’ questioning of Mark Zuckerberg in 2018 on how Facebook dealt with users’ personal data, the company established the 90-day lock-out policy for apps that year. However, the lock-out did not work as intended.
A company rep stated: “We haven’t seen evidence that this issue resulted in sharing information that was inconsistent with the permissions people gave when they logged in using Facebook.”
Facebook has also simplified its platform terms and developer policies to provide clearer guidance on data usage and sharing, as well as respecting users’ privacy when using its platform.
Facebook stated: “These new terms limit the information developers can share with third parties without explicit consent from people. They also strengthen data security requirements and clarify when developers must delete data.”
David Gargaro has been providing content writing and copy editing services for more than 20 years. He has worked with companies across numerous industries, including (but not limited to) advertising, publishing, marketing, real estate, finance, insurance, law, automotive, construction, human resources, restoration services, and manufacturing. He has also managed a team of freelancers as the managing editor of a small publishing company.
-
Bigger salaries, more burnout: Is the CISO role in crisis?
In-depth CISOs are more stressed than ever before – but why is this and what can be done?
By Kate O'Flaherty Published
-
Cheap cyber crime kits can be bought on the dark web for less than $25
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott Published
-
Meta to pay $725 million in Cambridge Analytica lawsuit settlement
News The settlement closes the long-running lawsuit into how Facebook's owner, Meta, handled the Cambridge Analytica scandal
By Ross Kelly Published
-
Meta's earnings are 'cause for concern' and 2023 looks even bleaker
Analysis Calls for investor faith in metaverse tech only emphasise the worries that its investment strategy won't pay off
By Rory Bathgate Published
-
Microsoft and Meta announce integration deal between Teams and Workplace
News Features from both business collaboration platforms will be available to users without having to switch apps
By Connor Jones Published
-
Facebook is shutting down its controversial facial recognition system
News The move will see more than a billion facial templates removed from Facebook's records amid a push for more private applications of the technology
By Connor Jones Published
-
'Changing name to Meat': Industry reacts to Facebook's Meta rebrand
News The rebrand attempts to provide a clearer distinction between Facebook and its umbrella company
By Connor Jones Published
-
Facebook's Oversight Board demands more transparency
News Board bashed the social media giant for its preferential treatment of certain high-profile accounts
By Danny Bradbury Published
-
Facebook claims AI managed to reduce hate speech by 50%
News The social media platform has hit back at claims the tech it uses to fight hate speech is inadequate
By Sabina Weston Published
-
Facebook to hire 10,000 workers across the EU
News The high-skilled jobs drive is a “vote of confidence” in the European tech industry
By Jane McCallion Published