TTB White LOGO TB
  • News
  • PC & Hardware
  • Mobiles
  • Gaming
  • Electronics
  • Gadget
  • Reviews
  • How To
Trending
Google Discover Now Adds AI Summaries, Threatening Publisher Traffic
Meta Now Fixes AI Chatbot Flaw Exposing Private User Prompts
Apple’s New Keyboard Patent Describes a Removable Mouse Key
AirPods Pro 2 Hearing Support Now Available in 13 More Countries
Meta Files to Restart H20 Chip Sales as It Builds 5 GW Hyperion Cluster
Thursday, Jul 17, 2025
The Tech BasicThe Tech Basic
Font ResizerAa
Search
  • News
  • PC & Hardware
  • Mobiles
  • Gaming
  • Electronics
  • Gadget
  • Reviews
  • How To
Follow US
Meta
The Tech Basic > News > Meta Now Fixes AI Chatbot Flaw Exposing Private User Prompts
News

Meta Now Fixes AI Chatbot Flaw Exposing Private User Prompts

Salman Akhtar
Last updated: 16 July 2025 15:29
Salman Akhtar
Share
Image Source: Mashable
SHARE

The Meta AI chatbot has a vulnerability that was revealed by a security researcher, Sandeep Hodkasia, that enabled logged-in users to see user prompts and answers that were kept private. In the process of experimenting with the regenerate option, Hodkasia realized that each prompt with its corresponding AI bot response had a numerical ID attached to it. By intercepting the network traffic, he could alter that number and retrieve another user’s conversation history.

Contents
Technical Details Behind the LeakBug Bounty and Patch DeploymentImplications for AI Privacy and SecurityLessons for AI Platform ProvidersMeta AI’s Early Launch Challenges
Meta
Image Source: TechJuice

Technical Details Behind the Leak

A prompt Metauser acquires an easily guessable ID in its back end when it is edited. The system did not ensure that it checked that the prompt was owned by the requester after retrieving the stored dialogue. Consequently, a substantial amount of confidential prompts and content that is produced by automating subsequent changes to an ID could be scraped by any user who does not require links or attachments.

Bug Bounty and Patch Deployment

Hodkasia privately reported the issue to Meta on December 26, 2024, and received a $10,000 reward under the company’s bug bounty program. Meta said that yesterday, it pushed a server-side fix on January 24, 2025, and was unable to find any evidence it was ever exploited in the wild.

Implications for AI Privacy and Security

This incident highlights the novel privacy risks introduced by AI assistants. Unlike traditional web apps, it is possible to leak conversations simply by manipulating numeric identifiers. Experts warn that AI platforms must enforce strict access controls and unpredictable ID schemes to prevent unauthorized data disclosure.

Lessons for AI Platform Providers

AI developers should treat prompts and responses as sensitive user data and apply the same authorization checks used for other personal information. Such attacks on guessable IDs can be thwarted by randomizing or hashing the internal identifiers. Expansive logging and anomaly detection are also necessary to identify the rapid ID enumeration effort.

Meta
Image Source: The Times of India

Meta AI’s Early Launch Challenges

Meta AI came out at the beginning of 2025 as the competitor to ChatGPT but suffered early setbacks in terms of privacy. There are users who sent confidential conversations to the community Discover feed by mistake, which is why Meta introduced pop-up messages. The irregular proactive leak issue is an eye-opener that calls for continuous security checks as the AI capabilities undergo changes.

The fix of this bug supports the significance of vulnerability disclosure and strong patching of AI services proactively. With the increased use of AI chatbots, people should be assured that their chats stay confidential and secure. Rapid action and reward to the researcher by Meta is an excellent example for the industry.

TAGGED:AIMeta
Share This Article
Facebook Reddit Copy Link Print
Share
Salman Akhtar
By Salman Akhtar
View enlightening tech pieces written by Salman Keep up with the most recent news, advice, and trends in the field of technology.

Let's Connect

FacebookLike
XFollow
PinterestPin
InstagramFollow
Google NewsFollow
FlipboardFollow

Popular Posts

Google Discover

Google Discover Now Adds AI Summaries, Threatening Publisher Traffic

Salman Akhtar
Apple’s New Keyboard

Apple’s New Keyboard Patent Describes a Removable Mouse Key

Salman Akhtar
AirPods Pro 2

AirPods Pro 2 Hearing Support Now Available in 13 More Countries

Salman Akhtar
Meta

Meta Files to Restart H20 Chip Sales as It Builds 5 GW Hyperion Cluster

Salman Akhtar

You Might Also Like

Nvidia
News

Nvidia to Resume H20 AI Chip Sales in China After Whiplash

Meta
News

Meta Follows YouTube with Crackdown on Unoriginal Facebook Posts

Google Gemini
News

Google Gemini Flaw Exposes Email Summaries to Hidden Phishing

xAI and Grok
News

xAI and Grok Apologize After Chatbot’s Antisemitic Outburst

Social Networks

Facebook-f Twitter Instagram Pinterest Rss

Company

  • About Us
  • Our Team
  • Contact Us

Policies

  • Disclaimer
  • Privacy Policy
  • Cookies Policy
Latest
iPhone 17 Pro Copper-Orange Color Leaked With Full Series Palette
China Demand Dips as Apple Sees Double‑Digit Gains Elsewhere
Google Merges Chrome OS and Android into One Unified Platform
Meta Acquires Play AI to Advance Its Generative Voice Technology
Delayed by Siri Enhancements Apple Smart Home Hub Will Arrive in 2026

© 2024 The Tech Basic INC. 700 – 2 Park Avenue New York, NY.

TTB White LOGO TB
Follow US
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?