Facebook flaw could have allowed an attacker to hijack accounts

If you’re a security researcher in search of a fat bug bounty, Facebook must look like a good place to start your next hunt. The site has suffered a lot of niggling security flaws in recent times, to which can now be added a new Cross Site Request Forgery (CSRF) protection bypass flaw that could have allowed an attacker to hijack a user’s account in several ways.

Read full news article on Naked Security