Vulnerabilities

Meta Paid Out $4 Million via Bug Bounty Program in 2025

The total amount of money given to bug bounty hunters by the social media giant has reached $25 million.

Meta bug bounty program

Meta has paid out $4 million through its bug bounty program in 2025, which brings the total awarded by the social media giant since the creation of the program to more than $25 million. 

Meta has received roughly 13,000 vulnerability reports this year and 800 of them have been rewarded. 

Three reports have been highlighted by the company. One referred to CVE-2025-59489, a Unity vulnerability that prompted action from both Microsoft and Steam. In the case of Meta, it could have allowed malicious applications installed on Quest VR headsets to manipulate Unity applications and execute arbitrary code.

Another report highlighted by Meta was submitted by researchers from the University of Vienna, who described a method for enumerating WhatsApp accounts at scale. 

The researchers used open source tools to generate possible phone numbers, verified whether they are associated with WhatsApp accounts, and compiled publicly accessible information.

Another bug report targeting WhatsApp came from a Meta analyst, who found an incomplete validation issue that could have been exploited to trigger the processing of content from an arbitrary URL on a user’s device.

Advertisement. Scroll to continue reading.

The company says WhatsApp clients and server infrastructure are important targets, but it’s not easy to find vulnerabilities. In response to feedback from researchers, Meta has decided to create a tool that should make it easier to research WhatsApp-specific technologies. 

This tool, called WhatsApp Research Proxy, is designed for analyzing the messaging application’s network protocol. The tool is currently only available to some long-time bug bounty hunters. More researchers will later be invited to test the tool, and the ultimate goal is to make it available to everyone. 

Related: Apple Bug Bounty Update: Top Payout $2 Million, $35 Million Paid to Date

Related: Google Paid Out $12 Million via Bug Bounty Programs in 2024

Related: Google Offers Up to $20,000 in New AI Bug Bounty Program

Related: Microsoft Boosts .NET Bounty Program Rewards to $40,000

Related Content

Artificial Intelligence

Anthropic's Mythos is accelerating vulnerability discovery to machine speed, forcing the bug bounty industry and offensive security teams to adapt to a future where...

Privacy & Compliance

The Meta-owned communications app is filing a federal court contempt order against NSO.

Data Breaches

The social media giant has informed authorities about the impact of the recent attack involving an account recovery support tool.

Vulnerabilities

The vulnerabilities were reported to Meta through its bug bounty program and were patched with updates released earlier this year.

Vulnerabilities

Researchers found more than 80 high-impact cloud and AI vulnerabilities during the event, which had a $5 million prize pool.

Artificial Intelligence

Through the new program, OpenAI will reward reports covering design or implementation issues leading to material harm.

Privacy

Meta does not plan on fixing the vulnerability because it involves the use of a modified client application.

Fraud & Identity Theft

Several major tech and retail companies have signed an industry accord against online scams and fraud.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version