Instagram vulnerability: private posts exposed without authentication
Affected Platform: Instagram Exposure to private Instagram posts via polaris_timeline_connection Complete technical analysis of an officially denied server-side vulnerability...
Exposure to private Instagram posts via polaris_timeline_connection
Complete technical analysis of an officially denied server-side vulnerability
The affected platform: Instagram
detained by: Meta
Perioada descoperirii: Octombrie 2025
Durata disclosure-ului: 102 zile
Tip vulnerabilitate: Server-side authorization bypass
Impact: Unauthorized access to private content (images + descriptions)
Status final: Patch applied in silence, closed case as Not Applicable
1. Introducere
This article documents A real, exploitable and proven vulnerability from the Instagram (mobile web) infrastructure, which allowed acces complet neautentificat in posts belonging to accounts set as private.
Although the problem was Corrected demonstrably Shortly after the report, Meta refused to acknowledge its existence, claiming it was never reproducible.
This is not an opinion, but a Technical and chronological reconstructionBased on:
-
Video evidence with cryptographic hash.
-
scripturi PoC,
-
the network logs,
-
commit-uri Git timestamp-ate,
-
Official mail address.
2. Contextul descoperirii
The vulnerability has been discovered. accidentalWorkflow automation tool for HTTP requests.
Analyzing HTML responses returned by Instagram mobile webI noticed an unusual behavior:
-
Media content was returned in HTML.
-
Although the application was not fully authenticated,
-
The target profile is defined as private.
Initially, the assumptions taken into account were:
-
cache CDN defectuos,
-
bleed de sesiune,
-
Local test error.
All were eliminated through repeated and controlled testing.
Confirming the vulnerability
To exclude any possibility of error, the test was repeated on propriul meu cont privat:
-
Contul a fost setat private
-
A new post has been posted.
-
Normal spread is expected.
-
S-a trimis o cerere GET No login, cookie, token or session
Rezultatul:
-
The post was present in response.
-
imaginea se putea accesa direct din CDN,
-
The description was included.
This step is essential: nu exista niciun vector de atac „extern”.
The Instagram server generates private data for unauthenticated users.
Detailed technical description
4.1 Endpoint-ul
Cererea:
-
nu include cookie-uri
-
nu include token-uri
-
nu include headere de autentificare
The only requirement is the use of headere specifice mobile (User-Agent / Accept).
4.2 Response of the server
The server returns the HTML that contained JSON embeduit.
In the structure of this JSON appeared the object:
With the following relevant structure:
4.3 Why it is critical
-
edges[] nu ar trebui populat pentru conturi private
-
The population involves Verification of server-side authorization
-
The CDN serves valid content, because the backend has exposed it
This is not a front-end bug.
This is not a cache bug.
It is a logical authorization error in the backend.
5. Proof of Concept (PoC)
A Python script has been created that:
-
Send an unauthenticated request
-
Extrage JSON-ul embeduit
-
Parcurge polaris_timeline_connection.edges
-
Get the display_url
-
Direct access to private content from CDN
Scriptul a fost:
-
rulat local
-
filmat
-
Used on third-party accounts Only with explicit consent.
Controlled testing
Official testing was strictly limited to licensed accounts.
Rezultate:
-
Total conturi testate: 7
-
Conturi vulnerabile: 2 (~28%)
-
Conturi neafectate: 5
The observations:
-
vulnerabilitatea era Conditionally
-
nu afecta toate conturile private
-
The first evidence suggests a correlation with vechimea contului
-
The exact cause has not been determined
This conditional nature increases the severity of the problem because:
-
It is difficult to detect.
-
It is hard to confirm as resolved.
-
It is easy to deny.
Disclosure to Meta – Complete Chronology
October 12, 2025
-
Previous PostPrevious Meta Bug Bounty
-
Includea:
-
Technical Explanation
-
script PoC
-
Video demonstration
-
Reply to Meta:
Closed case as “CDN caching issue”.
13–October 15, 2025
-
Raport nou, reformulat explicit ca server-side authorization bypass
-
Starting the dialogue
The Actions:
-
Meta requests test on their account → not vulnerable
-
Meta requests vulnerable account → provided with consent
-
The vulnerability is demonstrated again.
-
Sunt trimise:
-
video-uri
-
script
-
Explanation of the Trigger Status
-
October 16, 2025
-
The vulnerability no longer works.
-
All previously affected accounts return edges: []
There is no:
-
notificare
-
confirmare
-
Explained
October 27, 2025
The official answer:
“We cannot reproduce this problem.
The case is closed as Not Applicable.
8. Starea „trigger” – indiciu critic
During operation, a consistent indicator was:
-
Private account displayed with 0 followers / 0 following
-
story ring prezent
-
Timeline populated with real data
This inconsistency indicates:
-
un state intern corupt
-
an execution stream where authorization checks are skipped
What the target did not do
-
Nu a cerut loguri de debug Au fost oferite explicit (X-FB-Debug headers). Ignorate.
-
He did not analyze the conditional nature The comparative list of affected accounts was ignored.
-
There is no root cause analysis. “Infrastructure changes” ≠ security analysis.
Without RCA, there is no guarantee that:
-
problema nu reapare,
-
The same bug class does not exist anywhere else.
Evidence and Integrity
Filed and versioned:
-
script PoC
-
Capture before and after
-
4 video-uri cu timestamp + SHA256
-
Full archive of Meta Communications
-
Logs of network
-
istoric Git public
Dovezile nu pot fi fabricate retroactiv.
11. Impact real
Instagram is serving peste 1 miliard de utilizatori.
A bug that:
-
It only affects some private accounts.
-
It leaves no visible traces.
-
Notify the users.
este extrem de periculos.
Users are confident that private Meaning is private.
Why this disclosure is public
-
standardul industriei: 90 zile
-
Meta a avut 102 zile
-
The exploit no longer works.
-
There was no recognition or transparency.
Scopul acestui articol:
-
Historical documentary
-
Independent verification
-
Public Responsibility
13. Concluzie
The real question is not:
“Does it work today?”
Ci:
Have personal data been exposed to unauthorized users?
Based on technical, chronological and cryptographic evidence:
da, au fost.
Technical Details
For those who want to go deeper:
-
Github& README — Overview and evidence links
-
TIMELINE.md with videos, images— Complete chronological record
-
**poc.py **— Proof-of-concept script
-
**official_communication/ **— Full Meta correspondence (PDF)
Before
After
ZebraByteeditorial material on digital security, infrastructure, privacy and compliance, kept in the company's technical archive.