Instagram Security Flaw: A security vulnerability in Instagram exposed the private information of many users, including personal photos and captions that could be viewed without logging into the site or following a targeted user. The vulnerability was found by independent security researcher Jatin Banga and has been addressed by Meta since then. The problem had afflicted Instagram’s mobile web interface, and it raised questions about the handling of private content on the backend, particularly for users with private accounts.

What Caused the Security Issue

Banga said the cause of the flaw was inadequately stringent server-side authorisation checks on the Instagram mobile web platform. In certain circumstances, a web request combined with specific mobile browser headers could bypass normal access restrictions.

ALSO READ: Best Music Streaming App In 2026: My Real Experience With Spotify, Apple Music, YouTube Music, And Amazon Music

Instead of blocking unauthorised access, Instagram’s servers sometimes returned backend data that included:

- Direct links to private photos and videos hosted on Meta’s content delivery network

- Captions linked to those private posts

The problem was inconsistent and did not affect all private accounts, which made detection more difficult.

What we know so far

During testing, around 28 per cent of sampled private accounts were found to be vulnerable, while others remained fully protected. This selective exposure suggested the flaw was related to a specific backend state or session-handling condition rather than a platform-wide failure.

Because the issue only impacted certain accounts, it could have gone unnoticed for a long time without targeted testing.

ALSO READ: Amazon Layoffs 2026: 16,000 Employees To Lose Jobs As Part Of Bigger 30,000 Job Cut Plan, India Takes The Worst Hit

The vulnerability was submitted to Meta on 14 October 2025, and the bug had already been discovered in a third-party feed. Within a few days, Meta fixed the issue. The company subsequently dismissed the report and said that "the issue was addressed with infrastructure updates rather than through a dedicated patch."

The vulnerability has stopped being exploited for now, the latest available evidence shows.

Banga shares his concern about how this was handled, pointing out that security bugs that only hit some users are harder to spot and fix. He also said that “Partial exposure vulnerabilities can often be more dangerous as they likely won’t prompt widespread alerts or an immediate investigation.”