Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Meta Paid Out $4 Million via Bug Bounty Program in 2025

The total amount of money given to bug bounty hunters by the social media giant has reached $25 million.

Meta bug bounty program

Meta has paid out $4 million through its bug bounty program in 2025, which brings the total awarded by the social media giant since the creation of the program to more than $25 million. 

Meta has received roughly 13,000 vulnerability reports this year and 800 of them have been rewarded. 

Three reports have been highlighted by the company. One referred to CVE-2025-59489, a Unity vulnerability that prompted action from both Microsoft and Steam. In the case of Meta, it could have allowed malicious applications installed on Quest VR headsets to manipulate Unity applications and execute arbitrary code.

Another report highlighted by Meta was submitted by researchers from the University of Vienna, who described a method for enumerating WhatsApp accounts at scale. 

The researchers used open source tools to generate possible phone numbers, verified whether they are associated with WhatsApp accounts, and compiled publicly accessible information.

Another bug report targeting WhatsApp came from a Meta analyst, who found an incomplete validation issue that could have been exploited to trigger the processing of content from an arbitrary URL on a user’s device.

Advertisement. Scroll to continue reading.

The company says WhatsApp clients and server infrastructure are important targets, but it’s not easy to find vulnerabilities. In response to feedback from researchers, Meta has decided to create a tool that should make it easier to research WhatsApp-specific technologies. 

This tool, called WhatsApp Research Proxy, is designed for analyzing the messaging application’s network protocol. The tool is currently only available to some long-time bug bounty hunters. More researchers will later be invited to test the tool, and the ultimate goal is to make it available to everyone. 

Related: Apple Bug Bounty Update: Top Payout $2 Million, $35 Million Paid to Date

Related: Google Paid Out $12 Million via Bug Bounty Programs in 2024

Related: Google Offers Up to $20,000 in New AI Bug Bounty Program

Related: Microsoft Boosts .NET Bounty Program Rewards to $40,000

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Barry Childe has joined data sciences tech company Datavault AI as Chief Information Security Officer.

John DeSimone, the former CEO of Nightwing, has been named Chief Operating Officer at Everfox.

Sectigo has appointed Prem Hareesh as Corporate Chief Technology Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.