A security breach is affecting nearly 50 million Facebook accounts.
The Facebook team revealed the news today, saying it was discovered on Tuesday afternoon.
“We’re taking this incredibly seriously and wanted to let everyone know what’s happened and the immediate action we’ve taken to protect people’s security,” said a release from the social media giant.
“Our investigation is still in its early stages. But it’s clear that attackers exploited a vulnerability in Facebook’s code that impacted ‘View As,’ a feature that lets people see what their own profile looks like to someone else.”
According to Facebook, the breach allowed them to steal Facebook access tokens that could allow them to take over people’s accounts.
“Access tokens are the equivalent of digital keys that keep people logged in to Facebook so they don’t need to re-enter their password every time they use the app,” the release explains.
Facebook says the vulnerability has now been fixed and law enforcement has been informed.
Access tokens for the affected 50 million accounts have also been reset to protect security, as have the access tokens for an additional 40 million accounts as a precautionary measure.
As a result, those 90 million people will now have to log back into Facebook, as well as any of their other apps that use the Facebook login.
The ‘View As’ feature has temporarily been turned off while the company conducts a thorough review as well.
This attack exploited the complex interaction of multiple issues in our code. It stemmed from a change we made to our video uploading feature in July 2017, which impacted ‘View As.’ The attackers not only needed to find this vulnerability and use it to get an access token, they then had to pivot from that account to others to steal more tokens.
It hasn’t been determined if the affected accounts were misused, if any information was accessed or who was behind these attacks.
Facebook says there’s no need for any one to change their passwords.



