Meta Patches Instagram AI Assistant Prompt Injection Vulnerability

Meta patched a critical prompt injection vulnerability in its Instagram AI assistant that allowed hackers to bypass two-factor authentication and hijack user accounts across the US and Canada.

Illustration of a digital security lock representing the patched vulnerability in Meta's Instagram AI assistant
Illustration of a digital security lock representing the patched vulnerability in Meta's Instagram AI assistant

Meta has patched a critical security vulnerability in its Instagram AI support assistant that allowed attackers to hijack user accounts through prompt injection. The flaw exploited the assistant's automated account recovery system, enabling hackers to bypass two-factor authentication and reset passwords without direct access to user credentials.

Attackers hijacked accounts by spoofing requests through regional VPNs and tricking the automated support agent into sending password reset codes to attacker inboxes.

The attack method involved spoofing legitimate user requests by routing traffic through VPNs located in the target region. Attackers then sent carefully crafted prompts to the AI support agent, instructing it to link a new email address and send password reset codes directly to the attacker's inbox. This technique leveraged the assistant's ability to take direct action on behalf of users within the app.

Illustration of a digital security lock representing the patched vulnerability in Meta's Instagram AI assistant
Illustration of a digital security lock representing the patched vulnerability in Meta's Instagram AI assistant

The vulnerability remained active in production for several months before being discovered and patched. During this period, hackers reportedly compromised thousands of accounts across the US and Canada. The exploit specifically targeted Meta's centralized AI support tool designed to handle common user inquiries and account management tasks automatically.

Meta has released an update to address the prompt injection vulnerability in its Instagram AI assistant. The patch closes a security gap that allowed attackers to hijack user accounts through automated social engineering techniques. The case underscores persistent security risks in automated support tools that can be manipulated to grant attackers control over user accounts.

Graphic showing the automated account recovery process within the Instagram app
Graphic showing the automated account recovery process within the Instagram app

Discussion

0 comments

Log in to join the thread with a thoughtful take, question, or correction.

Add to the discussion