Massive Security Breach Found on Facebook and MySpace

CYBERSPACE — A developer has discovered a massive flaw in the security of both Facebook and MySpace that leaves users on both social networking sites vulnerable to massive identity theft and fraud.

The developer, Yvo Schaap, discovered the vulnerability, which works by taking advantage of how the two sites remember users' login information and use that information to activate certain Flash apps. Specifically, if a user checks the "remember me" box in the login modules of either site, and then use a Flash app that makes use of their login information, those actions would make their login information vulnerable to a hacker.

That basic problem could give hackers the power to build malicious Flash apps that could harvest users' other personal information, account numbers, photos, messages and everything else posted on either of the two sites.

Schaap emailed administrators at both sites. MySpace resolved the problem first, while Facebook followed close behind. That's the good news.

The bad news is that this vulnerability has been around for months, which means that any number of users may have had their information harvested.

Facebook has launched an investigation into the origin of the bug.

"The security of our users is a top priority for Facebook and we worked with the researcher who identified the issue to fix it," a representative for Facebook said. "We have not received any reports that it was ever exploited."

Tech analyst Jason Kincaid of TechCrunch.com criticized both sites for their lax security standards, but he saved his harshest words for Facebook

"Facebook is no longer just a platform for learning about your college buddies — it’s a serious business, used for photos and messages that can be very sensitive," he said. "I’ve heard of journalists who regularly use Facebook to reach out to potential sources, when secrecy is of the utmost importance. Apparently that’s not a good idea."

Tech-savvy developers may want to read Schaap's full description of the vulnerability, which apparently takes advantage of an imperfection in the programming of a file called "crossdomain.xml."

Related:  

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

2026 XBIZ LA Conference Schedule Announced

XBIZ is pleased to announce the release of the full show schedule for the XBIZ 2026 conference, set to take place Jan. 12-15 at the Kimpton Everly Hotel in Hollywood.

Needemand Joins ASACP as Corporate Sponsor

French startup company Needemand has signed on as the latest corporate sponsor for Association of Sites Advocating Child Protection (ASACP).

Utah State Legislator Proposes New 'Porn Tax'

A Utah state senator introduced a bill on Monday that would impose a 7% tax on the gross receipts of adult websites doing business in that state, plus require adult sites to pay an annual $500 fee.

Carlotta Champagne is LoyalFans' 'Featured Creator' for January

LoyalFans has named Carlotta Champagne as its Featured Creator for January.

Pineapple Support Relaunches Site

Pineapple Support has updated and relaunched its website.

Arcom-Targeted Sites Implement Age Verification in France

Five high-traffic adult websites based outside of France have implemented age verification as required under the nation’s Security and Regulation of the Digital Space (SREN) law, after receiving warnings from French media regulator Arcom.

Goddess Lilith Launches 'Adultpreneurs' Networking Site

Goddess Lilith has launched Adultpreneurs, a new community and networking site.

Adult Shoot Location Marketplace 'FckSpace' Launches

FckSpace, a new platform aimed at simplifying location sourcing for adult productions, is now live

Florida Attorney General Dismisses AV Suit Against Segpay

The Florida attorney general’s office on Monday agreed to dismiss claims against payment processor Segpay in a lawsuit over alleged noncompliance with the state’s age verification law.

FTC Weighs Reboot of 'Click to Cancel' Rulemaking Process

The Federal Trade Commission has invited public comments on a petition to renew trade regulation rulemaking concerning negative option plans, after a federal court previously vacated a “click-to-cancel” rule aimed at making it easier for consumers to cancel online subscriptions.

Show More