Facebook bug let websites read ‘likes’ and interests from a user’s profiletechcrunch.com • almost 5 years ago---
- Facebook has fixed a bug that let any website pull information from a user’s profile
— including their ‘likes’ and interests — without that user’s knowledge.
- In other words, a website could quietly siphon off certain bits of data from your
logged-in Facebook profile in another tab.
- "“This allowed information to cross over domains — essentially meaning that if a
user visits a particular website, an attacker can open Facebook and can collect
information about the user and their friends,” said Masas."
- The malicious website could open several Facebook search queries in a new tab, and
run queries that could return “yes” or “no” responses — such as if a Facebook user
likes a page, for example.
- It’s the latest in a string of data exposures and bugs that have put Facebook user
data at risk after the Cambridge Analytica scandal this year, which saw a political
data firm vacuum up profiles on 87 million users to use for election profiling —
including users’ likes and interests.