8 Sources
[1]
Exclusive: Meta fixes bug that could leak users' AI prompts and generated content
Meta has fixed a security bug that allowed Meta AI chatbot users to access and view the private prompts and AI-generated responses of other users. Sandeep Hodkasia, the founder of security testing firm Appsecure, exclusively told TechCrunch that Meta paid him $10,000 in a bug bounty reward for
[2]
Meta AI was leaking chatbot prompts and answers to unauthorized users
The flaw meant that any user could access the activity of another A vulnerability discovered last year by a cybersecurity expert found that Meta AI has been letting chatbot users access the private prompts and AI-generated responses of other users through a flaw. As reported by Cybernews, Meta
[3]
Meta patches worrying security bug which could have exposed user AI prompts and responses - and pays the bug hunter $10,000
The servers were not checking who had access rights to these identifiers A bug which could have exposed user's prompts and AI responses on Meta's artificial intelligence platform has been patched. The bug stemmed from the way Meta AI assigned identifiers to both prompts, and responses. As it
[4]
Meta paid a $10,000 bounty for a major AI privacy flaw
Meta addressed a security flaw within its Meta AI chatbot, which permitted users to view the private prompts and AI-generated responses of other individuals. Sandeep Hodkasia, founder of AppSecure, disclosed this vulnerability to TechCrunch, confirming Meta paid him a $10,000 bug bounty reward for
[5]
Meta Said to Have Fixed a Bug That Could Leak Users' Private AI Chats
Meta AI chatbots can now send users proactive follow-up messages Meta AI reportedly had a vulnerability that could be exploited to access other users' private conversations with the chatbot. Accessing this bug did not require breaking into Meta's servers or manipulating the code of the app;
[6]
Man Finds Major Bug In Meta's AI Platform That Exposed Private Chats - Receives $10,000 Reward For Proving The System Was Not As Secure As Claimed
With AI investments not slowing down any time soon, one would assume the technology is secure and that there would be no vulnerabilities in the existing platform, but that is not the case. Even if we see the tech giants, they are not free from errors, and their systems can be exploited. Such has
[7]
Meta AI Bug Exposed Private Conversations to Other Users
Meta investigated the issue and confirmed that the bug was fixed by January 24, 2025. Meta stated that there was no evidence of exploitation. The flaw highlights the fact that cutting-edge cybersecurity tools must go hand in hand with AI development. Meta acknowledged the bug and immediately fixed
[8]
Using Meta AI? A bug may have exposed your conversations to other users
A bug in Meta AI allowed users access others' private prompts and responses. If you've been using Meta's AI chatbot to generate text or images, there's an important privacy issue you should be aware of. A bug in the system may have allowed other users to see your private prompts and the responses
Share
Copy Link
Meta addressed a significant security vulnerability in its AI chatbot that could have exposed users' private prompts and AI-generated responses. The bug was discovered by a security researcher who received a $10,000 bounty for reporting it.
Meta, the parent company of Facebook, has addressed a critical security flaw in its AI chatbot that could have potentially exposed users' private conversations. The vulnerability was discovered by Sandeep Hodkasia, founder of security testing firm AppSecure, who reported it to Meta on December 26, 2024
1
.
Source: Dataconomy
The security flaw stemmed from how Meta AI assigned unique identifiers to user prompts and AI-generated responses. When a logged-in user edited their AI prompt to regenerate text or images, Meta's backend servers assigned a unique number to both the prompt and its corresponding AI-generated response
2
.Hodkasia discovered that by analyzing network traffic in his browser while editing an AI prompt, he could alter this unique number. This manipulation caused Meta's servers to return prompts and AI-generated responses belonging to other users, indicating that the servers were not adequately verifying user authorization
3
.The vulnerability could have had serious privacy implications. Many users share sensitive information with AI chatbots, including business documents, personal information, and even intimate life details. This data, if exposed, could potentially be exploited for various malicious purposes, such as highly customized phishing attacks, identity theft, or even ransomware deployment
3
.Related Stories

Source: Wccftech
Upon receiving Hodkasia's report, Meta took swift action to address the issue. The company deployed a fix on January 24, 2025, and awarded Hodkasia a $10,000 bug bounty for his responsible disclosure
4
.Meta spokesperson Ryan Daniels confirmed the fix and stated, "We found no evidence of abuse and rewarded the researcher"
1
. The company maintains that there is no evidence of malicious exploitation of the bug prior to its resolution.
Source: Digit
This incident highlights the ongoing challenges faced by tech giants as they rush to launch and refine AI products. It underscores the importance of robust security measures in AI applications, particularly those handling sensitive user data
5
.The vulnerability discovery comes in the wake of other privacy concerns surrounding Meta's AI chatbot. In a separate incident, some users inadvertently shared what they believed were private conversations publicly through the Meta AI app's discover feed
5
.As AI chatbots become increasingly integrated into various aspects of our digital lives, this incident serves as a reminder of the critical need for stringent security protocols and regular vulnerability assessments in AI-powered applications.
Summarized by
Navi
[4]
19 Mar 2026•Technology

13 Jun 2025•Technology

07 Aug 2025•Technology

1
Technology

2
Technology

3
Policy and Regulation
