Meta fixes privacy bug in AI chatbot that exposed user prompts

The bug was responsibly disclosed by Sandeep Hodkasia, founder of security testing firm AppSecure. He identified the flaw on December 26, 2024, and Meta deployed a fix nearly a month later, on January 24, 2025.

By  Storyboard18| Jul 16, 2025 1:29 PM
Beyond the privacy claims, plaintiffs also allege that Zuckerberg sold Facebook shares after anticipating a stock drop due to the Cambridge Analytica scandal, reportedly pocketing at least $1 billion. The defendants counter that evidence will show Zuckerberg did not trade on inside information and utilized a pre-planned stock-trading strategy designed to prevent insider trading.

Meta has patched a serious security vulnerability in its AI chatbot platform that allowed users to access private prompts and AI-generated responses from other users, according to a TechCrunch report.

The bug was responsibly disclosed by Sandeep Hodkasia, founder of security testing firm AppSecure, who told TechCrunch he received a $100,000 bug bounty for the discovery.

Hodkasia identified the flaw on December 26, 2024, and Meta deployed a fix nearly a month later, on January 24, 2025. A Meta spokesperson confirmed the issue to TechCrunch, stating that the company "found no evidence of abuse and rewarded the researcher."

The vulnerability stemmed from the way Meta AI handled editable prompts. Logged-in users could regenerate text and images by editing their original input. However, Meta's servers assigned each prompt-response pair a unique, sequential number - one that Hodkasia discovered could be manipulated. By intercepting and altering this number through browser network traffic analysis, he was able to retrieve other users' content without authorization.

“The prompt numbers were easily guessable,” Hodkasia told TechCrunch, warning that malicious actors could have exploited this by using automated tools to scrape user data at scale.

Although Meta confirmed that no exploitation was detected, the incident underscores the ongoing privacy and security challenges tech firms face as they race to roll out generative AI tools.

Meta’s standalone AI app, launched earlier this year to compete with platforms like ChatGPT, had already drawn criticism for privacy mishaps after some users unintentionally shared private conversations publicly.

First Published onJul 16, 2025 1:29 PM

SPOTLIGHT

Brand MarketingAI is rewriting the rules of B2B marketing with a human touch

Big-ticket buying decisions now demand more than just logic and product specs – they require trust, emotional connection, and brand stories that resonate.

Read More

Explained: What the Online Gaming Bill means for the industry, users and platforms

The Online Gaming Bill 2025 imposes severe penalties, allows warrantless search and seizure, and empowers a central authority to regulate the digital gaming ecosystem. It is expected to disrupt platforms, payment systems, and advertising in the sector. Here's all you need to know about the bill.