Meta AI assistant flaw let hackers hijack Instagram accounts
Meta AI’s customer‑support chatbot, introduced to help users resolve Instagram account issues, contained a security flaw that allowed attackers to change the e‑mail address linked to an account with little or no identity verification. By exploiting the weakness, hackers could reset passwords and take control of accounts, including high‑profile profiles such as Sephora’s official page, an archived White House Instagram account from the Obama presidency, and the developer Albert Renshaw’s handle. The vulnerability had been known to some researchers since March but became widely publicised in early May. Meta patched the bug over the weekend, and Vice‑President for Communications Andy Stone confirmed the fix and said the company is reviewing affected accounts. The incident reignited debate over the safety of delegating sensitive account‑recovery actions to generative AI without robust verification mechanisms.