Back

Vulnerability in Instagram Challenge System | Bypassing the “Locked” Screen via URL Manipulation

I discovered a logic flaw in Instagram’s “Challenge” system that allowed unauthorized users to bypass the mandatory security verification triggered by unusual activity. Normally, when Instagram detects a suspicious login or change, it locks the account and forces a verification code to be sent strictly to the original signup email. By manipulating specific URL parameters, I found a way to redirect this code to any new email address provided in the URL—effectively bypassing the original owner’s recovery info.

What Was the Vulnerability?

The core of this issue lies in the Instagram challenge infrastructure. This system is designed as a security checkpoint; if an account is flagged for unusual activity, Instagram is supposed to send a verification code ONLY to the original email used to create the account. This ensures that even if someone has the credentials, they cannot pass the security lock without access to the original signup email.

But this vulnerability lets a user completely bypass that requirement. By intercepting the challenge URL and modifying the path, I could trick the system into ignoring the secure signup email and instead sending the code to a completely new email address injected into the URL parameters.

Why Is This Dangerous?

This flaw can be abused in several serious ways:

  • Bypassing Security Locks: It allows someone to satisfy the “Unusual Activity” checkpoint using an unauthorized email.
  • Compromising Account Recovery: Instagram’s primary defense is sending codes to the original signup email to ensure the account returns to the rightful owner. This bug disabled that protection.
  • Persistent Access: If an account is locked for security, this bypass allows the person in possession of the account to unlock it using their own email, ignoring the original owner’s security data.

How to Reproduce the Issue

I tested this on the web interface. Here’s how the bypass worked:

  1. Trigger the Security Lock: Log into an account that has been flagged for unusual activity. Instagram displays the “Help Us Confirm You Own This Account” screen.
  2. Note the Challenge URL: The browser points to a URL like: https://www.instagram.com/challenge/action/{unique_identifier}.
  3. Modify the Path and Parameters: Manually alter the URL to: https://www.instagram.com/challenge/reset/{unique_identifier}/[email protected].
  4. Force the Interface Update: After navigating to the modified URL and hitting the browser’s Back button, the Instagram interface would update.
  5. Observe the Redirect: The page now displays the newly provided email as the destination for the code instead of the original signup info.
  6. Request and Submit: Instagram sends the valid verification token to the new email. Entering this code satisfies the “Unusual Activity” check and unlocks the account.

Impact on Instagram Security

This vulnerability was significant because it targeted the “checkpoint” mechanism—the final layer of protection Meta uses to verify account ownership. By allowing the code to be redirected to any new email, the bug undermined the integrity of the account lock mechanism and made the original signup email irrelevant during a security challenge.

Resolution and Fix

After discovering the vulnerability, I reported it through Meta’s Bug Bounty Program, providing detailed reproduction steps and a proof-of-concept video. Meta acknowledged the issue and implemented a fix to secure the system.

Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments