Instagram Investigates Reported Vulnerability Allowing Access to Private Content
A recent vulnerability identified in Instagram's server-side infrastructure permitted unauthorized access to private account posts. This issue highlights concerns regarding Meta's vulnerability disclosure processes and the overall effectiveness of its…
A recent vulnerability identified in Instagram's server-side infrastructure permitted unauthorized access to private account posts. This issue highlights concerns regarding Meta's vulnerability disclosure processes and the overall effectiveness of its user privacy protections.
The vulnerability was located in Instagram's mobile web interface and did not require authentication or a follower relationship to exploit. The attack involved sending an unauthenticated GET request to instagram.com/<private_username> with specific mobile headers. The server's response included HTML containing JSON data structures, notably the polaris_timeline_connection object, which provided CDN links to high-resolution private photos, captions, and other restricted content.
Testing indicated that the vulnerability affected approximately 28% of the accounts tested. The researcher reported this issue to Meta's bug bounty program on October 12, 2025. An initial misclassification by Meta as a CDN caching issue led to the closure of the case. However, a subsequent report and clarification prompted further engagement from Meta.
A recent vulnerability identified in Instagram's server-side infrastructure permitted unauthorized access to private account posts.
By October 16, 2025, the vulnerability was no longer present, suggesting Meta had corrected the issue. Nevertheless, Meta did not officially confirm the remediation or acknowledge the vulnerability. On October 27, Meta's response stated their inability to reproduce the issue, despite having made changes that resolved the vulnerability.
The researcher documented the issue comprehensively, including timestamped video evidence, proof-of-concept scripts, screenshots, network logs, and communication with Meta. The evidence was secured on GitHub with cryptographic integrity to prevent modification.
Concerns remain regarding Meta's handling of the disclosure, including the refusal of debug data, rejection of comparative account analysis, and lack of visible root cause analysis to ensure permanent resolution. The researcher, Jatin Banga, disclosed the vulnerability publicly after 102 days of attempting coordinated disclosure, exceeding the standard 90-day period.
Based on reporting by GBHackers.
