Skip to main content
Back to Blog
27 January 2026, byZebrabyte Breaches and incidents

Instagram vulnerability: private posts exposed without authentication

Instagram vulnerability: private posts exposed without authentication

Affected Platform: Instagram Exposure to private Instagram posts via polaris_timeline_connection Complete technical analysis of an officially denied server-side vulnerability...

Exposure to private Instagram posts via polaris_timeline_connection

Complete technical analysis of an officially denied server-side vulnerability

The affected platform: Instagram

detained by: Meta

Perioada descoperirii: Octombrie 2025

Durata disclosure-ului: 102 zile

Tip vulnerabilitate: Server-side authorization bypass

Impact: Unauthorized access to private content (images + descriptions)

Status final: Patch applied in silence, closed case as Not Applicable

1. Introducere

This article documents A real, exploitable and proven vulnerability from the Instagram (mobile web) infrastructure, which allowed acces complet neautentificat in posts belonging to accounts set as private.

Although the problem was Corrected demonstrably Shortly after the report, Meta refused to acknowledge its existence, claiming it was never reproducible.

This is not an opinion, but a Technical and chronological reconstructionBased on:

  • Video evidence with cryptographic hash.

  • scripturi PoC,

  • the network logs,

  • commit-uri Git timestamp-ate,

  • Official mail address.

2. Contextul descoperirii

The vulnerability has been discovered. accidentalWorkflow automation tool for HTTP requests.

Analyzing HTML responses returned by Instagram mobile webI noticed an unusual behavior:

  • Media content was returned in HTML.

  • Although the application was not fully authenticated,

  • The target profile is defined as private.

Initially, the assumptions taken into account were:

  • cache CDN defectuos,

  • bleed de sesiune,

  • Local test error.

All were eliminated through repeated and controlled testing.

Confirming the vulnerability

To exclude any possibility of error, the test was repeated on propriul meu cont privat:

  1. Contul a fost setat private

  2. A new post has been posted.

  3. Normal spread is expected.

  4. S-a trimis o cerere GET No login, cookie, token or session

Rezultatul:

  • The post was present in response.

  • imaginea se putea accesa direct din CDN,

  • The description was included.

This step is essential: nu exista niciun vector de atac „extern”.

The Instagram server generates private data for unauthenticated users.

Detailed technical description

4.1 Endpoint-ul

Cererea:

  • nu include cookie-uri

  • nu include token-uri

  • nu include headere de autentificare

The only requirement is the use of headere specifice mobile (User-Agent / Accept).

4.2 Response of the server

The server returns the HTML that contained JSON embeduit.

In the structure of this JSON appeared the object:

With the following relevant structure:

4.3 Why it is critical

  • edges[] nu ar trebui populat pentru conturi private

  • The population involves Verification of server-side authorization

  • The CDN serves valid content, because the backend has exposed it

This is not a front-end bug.

This is not a cache bug.

It is a logical authorization error in the backend.

5. Proof of Concept (PoC)

A Python script has been created that:

  1. Send an unauthenticated request

  2. Extrage JSON-ul embeduit

  3. Parcurge polaris_timeline_connection.edges

  4. Get the display_url

  5. Direct access to private content from CDN

Scriptul a fost:

  • rulat local

  • filmat

  • Used on third-party accounts Only with explicit consent.

Controlled testing

Official testing was strictly limited to licensed accounts.

Rezultate:

  • Total conturi testate: 7

  • Conturi vulnerabile: 2 (~28%)

  • Conturi neafectate: 5

The observations:

  • vulnerabilitatea era Conditionally

  • nu afecta toate conturile private

  • The first evidence suggests a correlation with vechimea contului

  • The exact cause has not been determined

This conditional nature increases the severity of the problem because:

  • It is difficult to detect.

  • It is hard to confirm as resolved.

  • It is easy to deny.

Disclosure to Meta – Complete Chronology

October 12, 2025

  • Previous PostPrevious Meta Bug Bounty

  • Includea:

    • Technical Explanation

    • script PoC

    • Video demonstration

Reply to Meta:

Closed case as “CDN caching issue”.

13–October 15, 2025

  • Raport nou, reformulat explicit ca server-side authorization bypass

  • Starting the dialogue

The Actions:

  • Meta requests test on their account → not vulnerable

  • Meta requests vulnerable account → provided with consent

  • The vulnerability is demonstrated again.

  • Sunt trimise:

    • video-uri

    • script

    • Explanation of the Trigger Status

October 16, 2025

  • The vulnerability no longer works.

  • All previously affected accounts return edges: []

There is no:

  • notificare

  • confirmare

  • Explained

October 27, 2025

The official answer:

“We cannot reproduce this problem.

The case is closed as Not Applicable.

8. Starea „trigger” – indiciu critic

During operation, a consistent indicator was:

  • Private account displayed with 0 followers / 0 following

  • story ring prezent

  • Timeline populated with real data

This inconsistency indicates:

  • un state intern corupt

  • an execution stream where authorization checks are skipped

What the target did not do

  1. Nu a cerut loguri de debug Au fost oferite explicit (X-FB-Debug headers). Ignorate.

  2. He did not analyze the conditional nature The comparative list of affected accounts was ignored.

  3. There is no root cause analysis. “Infrastructure changes” ≠ security analysis.

Without RCA, there is no guarantee that:

  • problema nu reapare,

  • The same bug class does not exist anywhere else.

Evidence and Integrity

Filed and versioned:

  • script PoC

  • Capture before and after

  • 4 video-uri cu timestamp + SHA256

  • Full archive of Meta Communications

  • Logs of network

  • istoric Git public

Dovezile nu pot fi fabricate retroactiv.

11. Impact real

Instagram is serving peste 1 miliard de utilizatori.

A bug that:

  • It only affects some private accounts.

  • It leaves no visible traces.

  • Notify the users.

este extrem de periculos.

Users are confident that private Meaning is private.

Why this disclosure is public

  • standardul industriei: 90 zile

  • Meta a avut 102 zile

  • The exploit no longer works.

  • There was no recognition or transparency.

Scopul acestui articol:

  • Historical documentary

  • Independent verification

  • Public Responsibility

13. Concluzie

The real question is not:

“Does it work today?”

Ci:

Have personal data been exposed to unauthorized users?

Based on technical, chronological and cryptographic evidence:

da, au fost.

Technical Details

For those who want to go deeper:

Before

After


Scris de Zebrabyte

ZebraByteeditorial material on digital security, infrastructure, privacy and compliance, kept in the company's technical archive.

ReceiveZebraByteanalytics and guidelines on cyber security, privacy and compliance.
ZebraByte

Framework-uri gestionate Managed frameworks

Can’t find the framework you are looking for?
Talk to us — we may be able to include it in the program.
Don’t see the framework you are looking for?
Reach out – it may already be supported in the program.

SOC 2 Type 1
ISO 27001
ISO 42001
CCPA
GDPR
ISO 27701
HIPAA
FERPA
CASA
SOC 2
Talk to an expert Talk to an expert