logo
Cybersecurity Firm AppSecure Identifies Critical Flaw in Meta.AI Leaking Users' AI Prompts and Responses, Rewarded $10,000

Cybersecurity Firm AppSecure Identifies Critical Flaw in Meta.AI Leaking Users' AI Prompts and Responses, Rewarded $10,000

Yahoo17-07-2025
SINGAPORE, July 17, 2025--(BUSINESS WIRE)--AppSecure, a cybersecurity firm specializing in penetration testing and red teaming, has discovered a critical vulnerability in Meta.AI, Meta's generative AI chatbot platform. If left unaddressed, the flaw could have allowed other users' data and private AI interactions to be leaked.
Sandeep Hodkasia, CEO and Founder of AppSecure Security, identified the issue during a security research exercise. His investigation revealed that Meta.AI's GraphQL API was unintentionally exposing prompts and outputs generated by other users. This oversight posed a risk of unauthorized access to personal and potentially sensitive conversations within the platform.
Fortunately, no evidence of misuse or exploitation was found. The flaw originated from a missing authorization check in Meta.AI's GraphQL API, specifically within the useAbraImagineReimagineMutation query. The system used a media_set_id to manage user interactions, but it didn't validate whether the person making the request actually owned that ID. As a result, any logged-in user could alter the media_set_id parameter and gain access to prompts and AI-generated content created by others.
AppSecure reported the vulnerability to Meta on December 26, 2024. They looked into the issue and rolled out a temporary fix on January 24, 2025, with it being permanently resolved on April 24, 2025.
In their official response, Meta said: "You demonstrated an issue where a malicious actor could access users' prompts and AI-generated media via a certain GraphQL query, potentially allowing an attacker to access users' private media. We mitigated this and found no evidence of abuse." Recognizing the significance of the finding, Meta awarded $10,000 for the key vulnerability and an additional $4,550 for related issues identified during the same investigation.
"This wasn't about chasing a bounty — it was about securing a system millions are starting to trust," clarifies Sandeep. "If a platform as robust as Meta.AI can have such loopholes, it's a clear signal that other AI-first companies must proactively test their platforms before users' data is put at risk."
As more companies rapidly deploy generative AI models, the surface area for potential attacks continues to grow. AppSecure's findings highlight the need for a proactive approach to security, especially in systems that handle user-generated content, prompt history, or model outputs.
AppSecure has a reputation for carefully and responsibly uncovering important security vulnerabilities. Many AI-focused companies trust AppSecure to help protect their systems. The company actively tests how users interact with AI platforms and examines the behind-the-scenes processes to find hidden flaws that could cause security risks. This hands-on approach helps businesses fix issues before they become serious threats.
"Security is not just about fixing problems after they appear; it's about anticipating risks and acting before damage occurs," adds Sandeep. "That's why leading companies work with us to identify real-world risks early and build AI platforms that stay secure and reliable from the very beginning."
About AppSecure Security
AppSecure Security is a CREST-accredited Penetration testing firm that identifies and addresses critical vulnerabilities through real-world attack simulations. The experienced team focuses on testing web applications, APIs, and networks to expose hidden risks before threats can cause harm. By following industry standards and taking a proactive approach, AppSecure helps businesses strengthen their defenses and stay ahead of evolving cyber challenges, making it a trusted partner for comprehensive security solutions.
View source version on businesswire.com: https://www.businesswire.com/news/home/20250717666906/en/
Contacts
Media Contact:Name: Sandeep HodkasiaWebsite: https://appsecure.securityEmail: pr@appsecure.security
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Leading AI startup soars 250% after increasing its IPO price range
Leading AI startup soars 250% after increasing its IPO price range

Yahoo

time23 minutes ago

  • Yahoo

Leading AI startup soars 250% after increasing its IPO price range

Leading AI startup soars 250% after increasing its IPO price range originally appeared on TheStreet. Wall Street's appetite for high-growth tech stocks is heating up again, and one rising star has taken full advantage. A fast-growing AI-powered platform, widely used by product development and design teams, wrapped up the roadshow for its proposed IPO last week — and the market response has been anything but ordinary. Only a few days ago, the company raised its initial public offering range from between $25 and $28 to between $30 and $32 per share, in a clear signal that investor demand was surging. 💵💰💰💵 Ultimately, the stock priced at $33 per share, $1 per share above even the revised range. That company? Figma (FIG), a collaborative design and product development platform that has transformed from a sleek web-based design tool into a powerful, AI-enabled software engine for product teams. On July 31, Figma made its public market debut on the New York Stock Exchange. Shares opened at an incredible $85, quickly surged past $112, and ultimately closed at $115.50, marking a 250% gain on its first day as a public company and pushing the company's market capitalization to nearly $68 from acquisition target to market darling Figma's journey to the public markets has been anything but conventional. Back in 2022, Adobe agreed to acquire the company for $20 billion. But that deal was scrapped a year later following pushback from UK antitrust regulators, who warned the merger would stifle competition and hurt innovation in the design software market. Rather than folding, Figma doubled down on product development and growth. The company now boasts over 13 million monthly users, with a customer base that includes Google, Microsoft, Netflix, and Uber. Its appeal extends far beyond traditional designers, with more than two-thirds of its users being non-designers, including engineers, marketers, and product managers who collaborate using the platform's connected toolsets. More Tech Stocks: Amazon tries to make AI great again (or maybe for the first time) Veteran portfolio manager raises eyebrows with latest Meta Platforms move Google plans major AI shift after Meta's surprising $14 billion move In its S-1 filing, Figma revealed second-quarter revenue of $247 million to $250 million, representing 40% year-over-year growth, and up to $12 million in operating income. More than 1,000 enterprise customers pay the company over $100,000 per year, underscoring its momentum at the high end of the market. Figma's IPO could rejuvenate the market The offering raised $1.2 billion, though the majority of proceeds went to existing shareholders, including venture capital backers like Greylock Partners, Index Ventures, Kleiner Perkins, and Sequoia Capital. Still, the size and enthusiasm surrounding the IPO are being seen as a watershed moment for tech listings in 2025. New York Stock Exchange President Lynn Martin said Figma's stunning performance could be a catalyst for a wave of new public offerings. "Given that Figma did so well with their pricing last night, and there is so much demand that has persisted in the order book this morning for this company, I think this will open the floodgates," she stated in a recent CNBC Figma is more than just a design tool Founded in 2012 and based in San Francisco, Figma has evolved into a full-stack collaboration engine. Its platform covers everything from digital whiteboarding to prototyping, interface design, and even developer handoff. With AI tools now embedded in the product experience, Figma is helping teams effectively transition from ideas to product launches faster and more cohesively. If the company's IPO is any indication, investors are betting that Figma is far more than a design startup. Time will tell whether it proves to be the next great software infrastructure company in the age of collaborative, AI-driven product development. But after its stellar public debut, it now has plenty of cash, visibility, and momentum to prove it. Leading AI startup soars 250% after increasing its IPO price range first appeared on TheStreet on Aug 1, 2025 This story was originally reported by TheStreet on Aug 1, 2025, where it first appeared. Error in retrieving data Sign in to access your portfolio Error in retrieving data Error in retrieving data Error in retrieving data Error in retrieving data

Someone Gave ChatGPT $100 and Let It Trade Stocks for a Month
Someone Gave ChatGPT $100 and Let It Trade Stocks for a Month

Yahoo

time37 minutes ago

  • Yahoo

Someone Gave ChatGPT $100 and Let It Trade Stocks for a Month

With $100 and a dream, one enterprising Redditor turned ChatGPT into a day trader, and the results so far have been pretty remarkable. In a post on r/Dataisbeautiful, the Redditor in question — real name Nathan Smith — described his project as a "6-month experiment to see how a language model performs in picking small, [under-covered] stocks with only a $100 budget." According to a chart shared on Reddit, this literal gamble is already paying off. Using GPT-4o, one of OpenAI's most advanced models, the bot-trader's stock portfolio has increased in value by 25 percent over its first month — though given that Smith only invested $100, that means he's only made $25 so far. What's more, that rise was significantly higher than two "small-cap" stock indexes, the Russell 2000 and XBI — in fact, the S&P 500 is up less than 3 percent over the past month — which suggests that ChatGPT very much picked correctly. To be fair, this is far from the first time someone's attempted such a gambit. Last December, researchers from Germany's Duisburg–Essen University published a paper in the journal Finance Research Letters finding that advanced OpenAI models did indeed seem to select money-making stocks. In an interview with Morningstar in June, meanwhile, University of Florida assistant finance professor Alejandro Lopez-Lira said that over years of simulating stock selection, ChatGPT wasn't all that great. "Our results on paper are much more optimistic than what the performance in reality would be with a reasonable investment size," Lopez-Lira told the finance blog. There's also a clear logical issue: if AI really was already better than the average human at picking stocks, then all traders would start using AI, changing the entire dynamics of the market and likely meaning that future trades wouldn't operate under the same logic. Responding to the larger trend, Smith decided, as he explained in a GitHub page documenting the experiment, to undertake the endeavor after seeing gimmicky ads that claimed AI could pick undervalued stocks and make investors mucho dinero. "It was obvious it was trying to get me to subscribe to some garbage, so I just rolled my eyes," he wrote. "Then I started wondering, 'How well would that actually work?'" As it turns out, it works quite well — but not without human input. Each day, as Smith's GitHub explains, he provides ChatGPT with trading data about its stock portfolio. Smith also said that he implements a strict "stop-loss" rules, which require a trader — in this case, ChatGPT — to immediately sell when a stock reaches a certain price. Though the experiment's stated purpose is to see whether AI can "manage money without guidance," that obviously hasn't happened just yet. Smith has, per his own acknowledgement, committed to daily homework with the trading data inputs until the end of December. Even if that task only takes a few minutes, it's still very much an example of human intervention into a project that, on its face, was meant to let ChatGPT do its thing. Still, it's a fascinating look into what AI, a bit of muscle grease, and $100 can do on the stock market — at least in an otherwise buoyant financial month. The real question? Whether the bot's portfolio will be up or down by the end of the experiment. More on ChatGPT: OpenAI's ChatGPT Agent Clicks "I Am Not a Robot" Button Without a Wink of Irony Error in retrieving data Sign in to access your portfolio Error in retrieving data Error in retrieving data Error in retrieving data Error in retrieving data

IPO market heats up: These 4 names prepare to go public next
IPO market heats up: These 4 names prepare to go public next

Yahoo

timean hour ago

  • Yahoo

IPO market heats up: These 4 names prepare to go public next

EquityZen head of market insight Brianne Lynch joins Market Domination with Josh Lipton to discuss the initial public offering (IPO) market in light of Figma's (FIG) recent public debut and whether companies need to have an artificial intelligence (AI) story to succeed. She also shares which private companies are likely to go public next. To watch more expert insights and analysis on the latest market action, check out more Market Domination. Which are the possible candidates in your opinion, that would be on your radar, who might be willing to test the public markets this year? Sure. So, you know, several of the names on our IPO outlook for the year have already gone public. But there are a few that we're still waiting on. One of the big ones being Klarna. This is a company that was planning to go public in the spring, tabled those plans given the volatility in the market post deliberation day. Uh but they're reportedly now looking at a September IPO. So that'll be, um, the next of several Fintech IPOs we've seen. You had Circle, um, Chime, eToro. So certainly, uh, Fintech is an area where we're seeing more activity and given Klarna's brand recognition, um, and you know, value in the market, that's one we have our eyes on. Right now if you're going to go public, Brian, do you have to have an AI story? Do you have to be able to just sprinkle some of that AI magic on your S-1? Yeah. I would say at a minimum you have to try. And Figma, you know, that's something that played into their story as well. They had so many case studies of their large enterprise clients saving, you know, lots of time and money because of the AI tools that they've built into their products. So, I think that's a table stake for any company that is looking to go public. And that might be the best option for public market investors at the time because you have to remember a lot of these pure play AI companies are still very young in their life cycle. They're less likely to be going public in the next few years. So yes, that's bringing more investors into the private markets to invest. Uh but to kind of capitalize on that interest, public companies or contenders to go public will also need to have that as part of their story. Do you think there there are certain kinds of private companies, Brian, that would be more likely to receive a warm welcome to the public markets in in this environment against this backdrop? Sure. I mean, we've seen a few examples of what has worked. You know, I talked about a little bit about the need for growth, the need for profitability, but when we look at the companies that may be coming next or even the IPOs we've seen in the first half of the year, it hasn't been just one sector or one industry. You've seen Fintech, um, you've seen crypto, which is obviously growing a lot and given, you know, the regulatory tailwinds, uh, we expect that to continue to be a hot market. Um, but then, you know, Netskope, another name on our outlook, that's a cybersecurity company. Um, StubHub, another one. That's an e-commerce player. So, it's definitely not a, you know, one sector narrative that's driving the market. It's more are you growing? Are you profitable? Do you have the brand name? Um, and do you have a a story that's exciting to investors, uh, especially, uh, given the lack of public companies relative to private companies now. Related Videos Berkshire Hathaway earnings: 'Perfect' stock to own when 'worried' Tesla must pay $240M+ for deadly 2019 car crash: What to know Fed Governor Adriana Kugler to resign Dow falls more than 500 points on jobs report, tariffs Error in retrieving data Sign in to access your portfolio Error in retrieving data Error in retrieving data Error in retrieving data Error in retrieving data

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store