Instagram korrigiert Sicherheitslücke bei Passwort-Reset, die E-Mail-Adressen und Telefonnummern preisgab
A critical logic bug in Instagram’s web-based password reset flow on June 6, 2026, exposed unredacted email addresses and phone numbers associated with user accounts, including those belonging to high-profile individuals such as Meta CEO Mark Zuckerberg and model Georgina Rodriguez.

Kurzfassung
Warum das wichtig ist
- A critical logic bug in Instagram’s web-based password reset flow on June 6, 2026, exposed unredacted email addresses and phone numbers associated with user accounts, including those belonging to high-profile individuals such as Meta CEO Mark Zuckerberg and model Georgina Rodriguez.
- Instagram’s parent company Meta deployed an emergency hotfix within hours of the disclosure, but not before proof-of-concept screenshots circulated widely on media, demonstrating the scope of the vulnerability.
- The vulnerability resided in Instagram’s web-based password reset interface, where the account recovery screen, designed to display only partially redacted recovery options, failed to properly mask sensitive contact data before presenting it to the requesting party.
SvyTech-Check
Redaktionelle Einordnung
Kernpunkt
Researchers discovered that a standard password reset for any given username, the response returned fully visible email addresses and phone numbers rather than the partially obscured versions Instagram...
Warum relevant
Proof-of-concept screenshots shared, including @vxunderground, showed login screens for accounts such as zuck revealing multiple associated emails alongside a linked phone number.
Einordnung
SvyTech ordnet die Meldung aus Cyber Security News als Teil des Themenfelds Technologie ein und verweist auf den Originalartikel, damit Leser Fakten, Quelle und Kontext nachvollziehen koennen.
Researchers discovered that a standard password reset for any given username, the response returned fully visible email addresses and phone numbers rather than the partially obscured versions Instagram normally shows (e.g., m***@fb.com ).
Proof-of-concept screenshots shared, including @vxunderground, showed login screens for accounts such as zuck revealing multiple associated emails alongside a linked phone number.
This constitutes a direct violation of Meta’s data minimization policies and potentially GDPR Article 25 obligations around privacy first spotted and publicly demonstrated on June 6, 2026, ’s account recovery infrastructure.

Technischer Hintergrund
Within hours of the demonstrations going viral, security researcher @Scot0xo confirmed on X that the flaw was a logic bug in the web reset flow, not an API credential leak or server-side breach that leaked sensitive account data before Meta responded with a targeted emergency hotfix.
Meta confirmed the patch was applied rapidly, echoing its standard response posture: “We fixed an issue that allowed an external party to request password reset emails for some Instagram users. There was no breach of our systems.” This incident is the latest in a string of Instagram security issues in 2026.
In January, a similar password reset abuse allowed third parties to trigger reset emails en masse, coinciding with the alleged leak of 17.5 million Instagram user records on dark web forums.

Sicherheitslage und Risiko
In early June, a separate vulnerability in Meta’s AI-powered support chatbot was exploited prompt injection to hijack high-profile accounts, including the White House archive page and U.S. Space Force accounts, link target accounts to attacker-controlled email addresses.
Security researchers have attributed the increasing frequency of these failures partly to architectural decisions around AI-driven automation of sensitive account functions, noting that granting AI systems privileged access to account recovery without robust identity verification creates systemic risk.
Meta confirmed that no widespread data exfiltration occurred in the June 6 incident. However, even brief exposure of unredacted account recovery data creates meaningful risk for phishing, SIM-swapping, and targeted account takeover attacks.
The enumeration of multiple email addresses tied to a single account could also help adversaries map identity infrastructure across services. Meta has not disclosed a CVE identifier for this logic flaw as of publication time. Users and security teams should continue monitoring Meta’s security advisories for further disclosure details.
Quelllink
Originalquelle: Cyber Security News
Thema weiterverfolgen
Interne Verlinkung
Im Kontext weiterlesen
Diese weiterfuehrenden Links verbinden das Thema mit relevanten Archivseiten, Schlagwoertern und inhaltlich nahen Artikeln.
Technologie Archiv
Weitere Meldungen aus derselben Hauptkategorie.
Mehr von Cyber Security News
Alle veroeffentlichten Inhalte derselben Quelle im Archiv.
Huawei-Team behauptet, DeepSeek-Modell mit 1,6 Billionen Parametern auf Ascend-910C-Chips nachtrainiert zu haben
Redaktionell verwandter Beitrag aus dem selben Themenumfeld.
Neuer US-Deal zielt darauf ab, Halbleitermaterial aus Aluminiumabfällen zu gewinnen
Redaktionell verwandter Beitrag aus dem selben Themenumfeld.
Quellenprofil
Quelle und redaktionelle Angaben
- Quelle
- Cyber Security News
- Originaltitel
- Instagram Fixes Password Reset Flaw That Exposes User Emails and Phone Numbers
- Canonical
- https://cybersecuritynews.com/instagram-password-reset-user-phone/
- Quell-URL
- https://cybersecuritynews.com/instagram-password-reset-user-phone/
Aehnliche Inhalte
Verwandte Themen und interne Verlinkung
Weitere Artikel aus aehnlichen Themenfeldern, damit Leser direkt im selben Kontext weiterlesen koennen.

Huawei-Team behauptet, DeepSeek-Modell mit 1,6 Billionen Parametern auf Ascend-910C-Chips nachtrainiert zu haben
Kopieren Sie den Link
07.06.2026
Live Redaktion
Neuer US-Deal zielt darauf ab, Halbleitermaterial aus Aluminiumabfällen zu gewinnen
Das Ames National Laboratory und die Indium Corporation haben eine neue Forschungs- und Entwicklungspartnerschaft angekündigt, die darauf abzielt, die Galliumproduktion in den Vereinigten Staaten zu erweitern.
07.06.2026
Live Redaktion
US-Armee entwickelt Durchbruchssensor zur präzisen Ortung von Funkgeräten im Gefecht
US-Armee-Wissenschaftler haben einen neuen Quantensensor vorgestellt, der die vollständige dreidimensionale Richtung Meilenstein könnte die Signalerkennung auf
07.06.2026
Live Redaktion
Samsung Mobile greift auf Qualcomm zurück: Exynos 2600 für Galaxy Z Flip 8 kostet durch LSI-Preiserhöhungen 270 Dollar pro Einheit.
Samsung LSI versuchte in den letzten Monaten, Samsung Mobile auszunutzen, indem es den Stückpreis seines Flaggschiff-Chips Exynos 2600 wiederholt erhöhte.
07.06.2026
Live Redaktion