
Cybersecurity Firm AppSecure Identifies Critical Flaw in Meta.AI Leaking Users' AI Prompts and Responses, Rewarded $10,000
, CEO and Founder of AppSecure Security, identified the issue during a security research exercise. His investigation revealed that Meta.AI's GraphQL API was unintentionally exposing prompts and outputs generated by other users. This oversight posed a risk of unauthorized access to personal and potentially sensitive conversations within the platform.
Fortunately, no evidence of misuse or exploitation was found. The flaw originated from a missing authorization check in Meta.AI's GraphQL API, specifically within the useAbraImagineReimagineMutation query. The system used a media_set_id to manage user interactions, but it didn't validate whether the person making the request actually owned that ID. As a result, any logged-in user could alter the media_set_id parameter and gain access to prompts and AI-generated content created by others.
AppSecure reported the vulnerability to Meta on December 26, 2024. They looked into the issue and rolled out a temporary fix on January 24, 2025, with it being permanently resolved on April 24, 2025.
In their official response, Meta said: 'You demonstrated an issue where a malicious actor could access users' prompts and AI-generated media via a certain GraphQL query, potentially allowing an attacker to access users' private media. We mitigated this and found no evidence of abuse.' Recognizing the significance of the finding, Meta awarded $10,000 for the key vulnerability and an additional $4,550 for related issues identified during the same investigation.
'This wasn't about chasing a bounty — it was about securing a system millions are starting to trust,' clarifies Sandeep. 'If a platform as robust as Meta.AI can have such loopholes, it's a clear signal that other AI-first companies must proactively test their platforms before users' data is put at risk.'
As more companies rapidly deploy generative AI models, the surface area for potential attacks continues to grow. AppSecure's findings highlight the need for a proactive approach to security, especially in systems that handle user-generated content, prompt history, or model outputs.
AppSecure has a reputation for carefully and responsibly uncovering important security vulnerabilities. Many AI-focused companies trust AppSecure to help protect their systems. The company actively tests how users interact with AI platforms and examines the behind-the-scenes processes to find hidden flaws that could cause security risks. This hands-on approach helps businesses fix issues before they become serious threats.
'Security is not just about fixing problems after they appear; it's about anticipating risks and acting before damage occurs,' adds Sandeep. 'That's why leading companies work with us to identify real-world risks early and build AI platforms that stay secure and reliable from the very beginning.'
About AppSecure Security
AppSecure Security is a CREST-accredited Penetration testing firm that identifies and addresses critical vulnerabilities through real-world attack simulations. The experienced team focuses on testing web applications, APIs, and networks to expose hidden risks before threats can cause harm. By following industry standards and taking a proactive approach, AppSecure helps businesses strengthen their defenses and stay ahead of evolving cyber challenges, making it a trusted partner for comprehensive security solutions.

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles
Yahoo
16 minutes ago
- Yahoo
Bloom Energy (BE) Rides AI Data Center Boom but Faces Cash Burn Risks
Bloom Energy Corporation (NYSE:) is one of the . On August 1st, BMO Capital analyst Ameet Thakkar raised the price target on the stock to $33.00 (from $18.00) while maintaining a 'Market Perform' rating. Bloom Energy reported its second quarter 2025 financial results on July 31st, which was the third straight quarter of quarterly record revenue and profits for the company. The firm beat revenue estimates ($401.2M versus the consensus estimate of $376.24M). '2Q results came in ahead of our estimates. Importantly, service gross margins improved further, which given large service backlog is positive as margins here have historically been weak. Order momentum within data center appears strong as evidenced by recent Oracle announcement and potential role in Crusoe/Tallgrass data center project in WY driving shares +39% since 7/23/25 announcement." A modern skyscraper illuminated in orange and blue, representing the energy sector of the US equity market. "That said, 2Q and YTD cash burn again significantly negative and with BE shares trading at 37x and 22x our 2026 and 2027 EBITDA estimate, we remain Market Perform. Raising target to $33.' Bloom Energy Corporation (NYSE:BE) develops solid-oxide fuel cell systems for on-site power generation, helping meet the growing energy demands of AI data centers. While we acknowledge the potential of BE as an investment, we believe certain AI stocks offer greater upside potential and carry less downside risk. If you're looking for an extremely undervalued AI stock that also stands to benefit significantly from Trump-era tariffs and the onshoring trend, see our free report on the best short-term AI stock. READ NEXT: 10 Must-Watch AI Stocks on Wall Street and Disclosure: None. Sign in to access your portfolio


Skift
33 minutes ago
- Skift
Airbnb's Brian Chesky: We're Open to Partnering With AI Chatbots
Airbnb's Brian Chesky is close to OpenAI CEO Sam Altman, but that doesn't mean that Airbnb will necessarily distribute its inventory through Altman's ChatGPT. Airbnb CEO Brian Chesky said during the company's second-quarter earnings call Wednesday that it is still "feeling out" the possibility of working with the big AI chatbots like ChatGPT, which he called "an incredibly compelling product." "We're certainly open to" integrating with major AI Chatbots, which could be a source of lead generation for Airbnb, Chesky said. Unlike which has partnerships with OpenAI, Amazon Web Services and Microsoft and sees generative AI chatbots as a new distribution channel, Airbnb has made no decisions yet about selling stays, Services or Experiences through major AI assistants. AI Chatbots Are
Yahoo
an hour ago
- Yahoo
Corporate Professional Turned AI Entrepreneur Manas Pathak Says Future Workforce Needs Entrepreneurial Mindset -- and the Ability to Think Like a Coder
PHOENIX, Aug. 6, 2025 /PRNewswire/ -- Manas Pathak, founder of the startups EarthEn Energy and Grid8 and former corporate professional at Intel Corporation, is calling for a fundamental shift in how the next generation is prepared for the future of work. His message is clear: tomorrow's workforce must be equipped with an entrepreneurial mindset and the ability to think like coders—not just code, but think in the structured, logical, and solution-oriented way coding teaches. After a successful corporate career, Pathak founded EarthEn Energy and Grid8, two startups focused on applying artificial intelligence to solve critical problems in energy and infrastructure. Through these ventures, he has seen firsthand how rapidly the landscape is evolving—and how unprepared many young professionals are to navigate it. "The future will not be linear, and no job is future-proof," says Pathak. "What is future-proof is the ability to spot opportunities and build solutions. Entrepreneurial thinking helps you identify what needs to be done. AI and coding skills help you actually do it." Pathak believes the traditional divide between "builders" and "thinkers" is collapsing. In today's world, employees need to be both. Whether climbing the ranks inside a company or launching their own startup, the combination of initiative, creative problem-solving, and technical fluency will be key to long-term relevance and success. "It's not just about writing lines of code—it's about developing a way of thinking that's analytical, structured, and deeply problem-oriented," says Pathak. "That mindset, which often comes from learning to code, is what gives people the power to act on the opportunities they discover." Pathak urges schools, universities, and companies to go beyond surface-level tech skills and cultivate deeper, foundational thinking. "We don't know exactly what the future looks like, but we know what it will demand," he adds. "People who can spot opportunity and build toward it—those are the ones who will thrive." About Manas Pathak With a background in corporate roles across the tech and energy sectors, Manas Pathak is now the founder of EarthEn Energy and Grid8, two startups at the intersection of artificial intelligence and energy infrastructure. Media contact:ask@ View original content to download multimedia: SOURCE EarthEn Energy Error in retrieving data Sign in to access your portfolio Error in retrieving data Error in retrieving data Error in retrieving data Error in retrieving data