Scan to download
BTC $62,845.39 +2.14%
ETH $1,664.65 +4.93%
BNB $596.87 +3.07%
XRP $1.13 +2.95%
SOL $65.69 +3.62%
TRX $0.3270 +1.05%
DOGE $0.0852 +2.64%
ADA $0.1623 +1.06%
BCH $221.42 +0.13%
LINK $7.81 +3.28%
HYPE $60.67 +4.94%
AAVE $62.60 +1.26%
SUI $0.7447 -0.12%
XLM $0.1984 -5.99%
ZEC $428.85 +14.55%
BTC $62,845.39 +2.14%
ETH $1,664.65 +4.93%
BNB $596.87 +3.07%
XRP $1.13 +2.95%
SOL $65.69 +3.62%
TRX $0.3270 +1.05%
DOGE $0.0852 +2.64%
ADA $0.1623 +1.06%
BCH $221.42 +0.13%
LINK $7.81 +3.28%
HYPE $60.67 +4.94%
AAVE $62.60 +1.26%
SUI $0.7447 -0.12%
XLM $0.1984 -5.99%
ZEC $428.85 +14.55%

GoPlus: Meta account recovery feature exposed to high-risk design flaws, which could directly leak users' sensitive information

2026-06-08 10:45:52
Collection

GoPlus posted on platform X that the Meta account recovery feature has been exposed to a high-risk design flaw, which could directly leak users' phone numbers, email addresses, and PII (Personally Identifiable Information). Attackers only need to input the META username without any login or verification to directly obtain the complete PII linked to the user, such as email addresses and phone numbers. This could pose significant risks to users, including: large-scale phishing attacks, SIM card swapping attacks, account takeover and identity theft, and targeted social engineering attacks.

Recommendations: Remove or change the leaked email/phone number as a recovery method; modify related account passwords and enable 2FA; do not click on any emails or messages related to "account anomalies," "verification," or "password reset"; set up multi-channel verification, which can be verified through official documents or other official social media channels.

app_icon
ChainCatcher Building the Web3 world with innovations.