Meta fixes privacy bug in AI chatbot that exposed user prompts

The bug was responsibly disclosed by Sandeep Hodkasia, founder of security testing firm AppSecure. He identified the flaw on December 26, 2024, and Meta deployed a fix nearly a month later, on January 24, 2025.

By  Storyboard18Jul 16, 2025 1:29 PM
Meta fixes privacy bug in AI chatbot that exposed user prompts
The vulnerability stemmed from the way Meta AI handled editable prompts. Logged-in users could regenerate text and images by editing their original input.

Meta has patched a serious security vulnerability in its AI chatbot platform that allowed users to access private prompts and AI-generated responses from other users, according to a TechCrunch report.

The bug was responsibly disclosed by Sandeep Hodkasia, founder of security testing firm AppSecure, who told TechCrunch he received a $100,000 bug bounty for the discovery.

Hodkasia identified the flaw on December 26, 2024, and Meta deployed a fix nearly a month later, on January 24, 2025. A Meta spokesperson confirmed the issue to TechCrunch, stating that the company "found no evidence of abuse and rewarded the researcher."

The vulnerability stemmed from the way Meta AI handled editable prompts. Logged-in users could regenerate text and images by editing their original input. However, Meta's servers assigned each prompt-response pair a unique, sequential number - one that Hodkasia discovered could be manipulated. By intercepting and altering this number through browser network traffic analysis, he was able to retrieve other users' content without authorization.

“The prompt numbers were easily guessable,” Hodkasia told TechCrunch, warning that malicious actors could have exploited this by using automated tools to scrape user data at scale.

Although Meta confirmed that no exploitation was detected, the incident underscores the ongoing privacy and security challenges tech firms face as they race to roll out generative AI tools.

Meta’s standalone AI app, launched earlier this year to compete with platforms like ChatGPT, had already drawn criticism for privacy mishaps after some users unintentionally shared private conversations publicly.

First Published on Jul 16, 2025 1:29 PM

More from Storyboard18

Brand Marketing

Maruti Suzuki just made this safety feature standard. But it will cost you

Maruti Suzuki just made this safety feature standard. But it will cost you

Brand Marketing

GCPL's ad spending up by 2.47% to Rs 1,369.21 crore in FY25

GCPL's ad spending up by 2.47% to Rs 1,369.21 crore in FY25

Brand Marketing

Bombay HC dismisses PIL against Prada over 'Kolhapuri-style' sandals

Bombay HC dismisses PIL against Prada over 'Kolhapuri-style' sandals

Brand Marketing

Labubu Doll sparks bizarre rumours, netizens link it to The Simpsons' infamous Pazuzu episode

Labubu Doll sparks bizarre rumours, netizens link it to The Simpsons' infamous Pazuzu episode

Brand Makers

GCPL reveals 3 pillars for growth model- Soap, insecticides, future-facing categories

GCPL reveals 3 pillars for growth model- Soap, insecticides, future-facing categories

Brand Marketing

Zepto Cafe scales down operations amid supply chain issues, staffing shortages

Zepto Cafe scales down operations amid supply chain issues, staffing shortages

Brand Makers

'Don't have a jet. But would like to have one': Deepinder Goyal

'Don't have a jet. But would like to have one': Deepinder Goyal