Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data
A security researcher discovered a critical vulnerability in Meta's Horizon Managed Solutions platform, allowing an attacker to access sensitive customer support data and manipulate support workflows. Meta patched the issue in April 2026 and rewarded the researcher with a $78,000 bug bounty.
A security researcher, Rony K Roy, identified a significant vulnerability in Meta’s Horizon Managed Solutions platform, a system used to manage Meta Quest devices and users. Initially described as having limited severity, further investigation revealed the flaw’s impact was considerably greater. Roy reported the vulnerability to Meta in January 2026, and the company subsequently released a patch in April 2026.
His analysis uncovered a series of interconnected issues, including a missing authorization mechanism, broken access control, and insecure direct object reference (IDOR) vulnerabilities. When combined, these flaws could have enabled an attacker to list Meta support case numbers and gain access to user conversations and support requests. Furthermore, the vulnerability allowed for the creation of fraudulent support requests, modification of existing workflows, and unauthorized user additions to support cases. The researcher is listed as one of Meta’s top researchers for 2026 due to this discovery.
Meta has not yet responded to SecurityWeek’s request for comment regarding Roy’s claims.