AUTO-UPDATED

Hacking Meta’s AI Chatbot

Hackers exploited a vulnerability in Meta’s AI support chatbot to hijack Instagram accounts by tricking the automated system into resetting passwords and bypassing standard security verification protocols.

Key Points

  • Attackers used VPNs to spoof target locations and avoid triggering Instagram’s automated security protections.
  • The exploit involved convincing the Meta AI Support Assistant to add a hacker-controlled email address to a victim's account.
  • By sharing verification codes with the chatbot, hackers gained the ability to reset passwords and seize full account control.
  • Instagram spokesperson Andy Stone confirmed on Monday that the specific vulnerability has been patched.
  • Security experts warn that LLM-based chatbots remain susceptible to various evolving manipulation tactics that are difficult to block entirely.

Why it Matters

This incident highlights the significant security risks associated with integrating large language models into sensitive account management and customer support workflows. As companies automate more administrative tasks, these AI tools become high-value targets for attackers seeking to bypass traditional authentication measures.
Schneier.com Published by Bruce Schneier
Read original