TTB White LOGO TB
  • News
  • PC & Hardware
  • Mobiles
  • Gaming
  • Electronics
  • Gadget
  • Reviews
  • How To
  • Login
  • Sign Up
Trending
Microsoft Launches Copilot Tasks Research Preview
Lenovo Teases Foldable Legion Go With 11.6 Inch Screen
How iOS 26 Prioritizes Alerts With Apple Intelligence
Mobile Game Installs Drop but Spending Climbs in 2025
Instagram Will Tell Parents When a Teen Searches for Suicide or Self Harm
Friday, Sep 18, 2026
The Tech BasicThe Tech Basic
Font ResizerAa
Search
Follow US
Meta
The Tech Basic > News > Meta Now Fixes AI Chatbot Flaw Exposing Private User Prompts
News

Meta Now Fixes AI Chatbot Flaw Exposing Private User Prompts

Salman Akhtar
Last updated: 16 July 2025 15:29
Salman Akhtar
Share
Image Source: Mashable
SHARE

The Meta AI chatbot has a vulnerability that was revealed by a security researcher, Sandeep Hodkasia, that enabled logged-in users to see user prompts and answers that were kept private. In the process of experimenting with the regenerate option, Hodkasia realized that each prompt with its corresponding AI bot response had a numerical ID attached to it. By intercepting the network traffic, he could alter that number and retrieve another user’s conversation history.

Contents
  • Technical Details Behind the Leak
  • Bug Bounty and Patch Deployment
  • Implications for AI Privacy and Security
  • Lessons for AI Platform Providers
  • Meta AI’s Early Launch Challenges
Meta
Image Source: TechJuice

Technical Details Behind the Leak

A prompt Metauser acquires an easily guessable ID in its back end when it is edited. The system did not ensure that it checked that the prompt was owned by the requester after retrieving the stored dialogue. Consequently, a substantial amount of confidential prompts and content that is produced by automating subsequent changes to an ID could be scraped by any user who does not require links or attachments.

Bug Bounty and Patch Deployment

Hodkasia privately reported the issue to Meta on December 26, 2024, and received a $10,000 reward under the company’s bug bounty program. Meta said that yesterday, it pushed a server-side fix on January 24, 2025, and was unable to find any evidence it was ever exploited in the wild.

Implications for AI Privacy and Security

This incident highlights the novel privacy risks introduced by AI assistants. Unlike traditional web apps, it is possible to leak conversations simply by manipulating numeric identifiers. Experts warn that AI platforms must enforce strict access controls and unpredictable ID schemes to prevent unauthorized data disclosure.

Lessons for AI Platform Providers

AI developers should treat prompts and responses as sensitive user data and apply the same authorization checks used for other personal information. Such attacks on guessable IDs can be thwarted by randomizing or hashing the internal identifiers. Expansive logging and anomaly detection are also necessary to identify the rapid ID enumeration effort.

Meta
Image Source: The Times of India

Meta AI’s Early Launch Challenges

Meta AI came out at the beginning of 2025 as the competitor to ChatGPT but suffered early setbacks in terms of privacy. There are users who sent confidential conversations to the community Discover feed by mistake, which is why Meta introduced pop-up messages. The irregular proactive leak issue is an eye-opener that calls for continuous security checks as the AI capabilities undergo changes.

The fix of this bug supports the significance of vulnerability disclosure and strong patching of AI services proactively. With the increased use of AI chatbots, people should be assured that their chats stay confidential and secure. Rapid action and reward to the researcher by Meta is an excellent example for the industry.

TAGGED:AIMeta
Share This Article
Facebook Reddit Copy Link Print
Share
Salman Akhtar
BySalman Akhtar
View enlightening tech pieces written by Salman Keep up with the most recent news, advice, and trends in the field of technology.

Let's Connect

FacebookLike
XFollow
PinterestPin
InstagramFollow
Google NewsFollow
FlipboardFollow

Popular Posts

Microsoft

Microsoft Launches Copilot Tasks Research Preview

Salman Akhtar
4 Min Read
Lenovo

Lenovo Teases Foldable Legion Go With 11.6 Inch Screen

Salman Akhtar
4 Min Read
iOS 26

How iOS 26 Prioritizes Alerts With Apple Intelligence

Salman Akhtar
3 Min Read
Mobile Game Installs

Mobile Game Installs Drop but Spending Climbs in 2025

Salman Akhtar
3 Min Read

You Might Also Like

Instagram
News

Instagram Will Tell Parents When a Teen Searches for Suicide or Self Harm

4 Min Read
Nvidia
News

Nvidia posts $68.1B quarter as AI boom accelerates Q4 growth

3 Min Read
Galaxy S26
News

Samsung Reinvents AI on Galaxy S26 With Triple Assistants

4 Min Read
Help Me Calculate Lethal Dose
Blog

How ‘Help Me Calculate Lethal Dose’ Chats Turned Into Cold-Blooded Motel Murders

4 Min Read

Social Networks

Facebook-f Twitter Instagram Pinterest Rss

Company

  • Home
  • Login
  • My Interests
  • My Saves
  • Register

Policies

  • Home
  • Login
  • My Interests
  • My Saves
  • Register
Latest
Gemini Automation Books Rides on Galaxy S26 and Pixel 10
Court Filing Probes Instagram Delay on Teen Protections
YouTube Upgrades Premium Lite With Background Play
Apple Hits New Sales Peak in Europe While Demand Softens Elsewhere
iPhone 18 Pro Could Redefine Selfies With 24MP Sensor

© 2024 The Tech Basic INC. 700 – 2 Park Avenue New York, NY.

TTB White LOGO TB
Follow US
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?