Skip to Content
logologo
AI Incident Database
Open TwitterOpen RSS FeedOpen FacebookOpen LinkedInOpen GitHub
Open Menu
Discover
Submit
  • Welcome to the AIID
  • Discover Incidents
  • Spatial View
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Submit Incident Reports
  • Submission Leaderboard
  • Blog
  • AI News Digest
  • Risk Checklists
  • Random Incident
  • Sign Up
Collapse
Discover
Submit
  • Welcome to the AIID
  • Discover Incidents
  • Spatial View
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Submit Incident Reports
  • Submission Leaderboard
  • Blog
  • AI News Digest
  • Risk Checklists
  • Random Incident
  • Sign Up
Collapse

Incident 1172: Meta AI Bug in Deployed Service Reportedly Allowed Potential Access to Other Users' Prompts and Responses

Description: A security researcher reported a vulnerability in Meta AI's deployed chatbot service that, under certain conditions, could allow an unauthorized user to view another user's prompts and AI-generated responses. The flaw reportedly involved guessable prompt IDs and insufficient server-side authorization checks. Meta reportedly fixed the issue in January 2025 and found no evidence of malicious exploitation, awarding the researcher a bug bounty.
Editor Notes: Timeline notes: The reported bug was filed 12/26/2024. Meta reportedly paid the security researcher who discovered the vulnerability, Sandeep Hodkasia, $10,000 for the bug bounty, and implemented the fix on 01/24/2025. Reporting on the incident arose in mid-July 2025, and it was ingested as a new incident ID on 08/15/2025.

Tools

New ReportNew ReportNew ResponseNew ResponseDiscoverDiscoverView HistoryView History

Entities

View all entities
Alleged: Meta and Meta AI developed and deployed an AI system, which harmed Meta users and General public.
Alleged implicated AI system: Meta AI

Incident Stats

Incident ID
1172
Report Count
1
Incident Date
2024-12-26
Editors
Daniel Atherton

Incident Reports

Reports Timeline

Incident OccurrenceMeta fixes bug that could leak users’ AI prompts and generated content
Loading...
Meta fixes bug that could leak users’ AI prompts and generated content

Meta fixes bug that could leak users’ AI prompts and generated content

techcrunch.com

Loading...
Meta fixes bug that could leak users’ AI prompts and generated content
techcrunch.com · 2025

Meta has fixed a security bug that allowed Meta AI chatbot users to access and view the private prompts and AI-generated responses of other users.

Sandeep Hodkasia, the founder of security testing firm AppSecure, exclusively told TechCrunch…

Variants

A "variant" is an AI incident similar to a known case—it has the same causes, harms, and AI system. Instead of listing it separately, we group it under the first reported incident. Unlike other incidents, variants do not need to have been reported outside the AIID. Learn more from the research paper.
Seen something similar?

Similar Incidents

Selected by our editors

Meta AI App Reportedly Publishes Personal Chats Without Users Fully Realizing

Apr 2025 · 3 reports
By textual similarity

Did our AI mess up? Flag the unrelated incidents

Loading...
YouTube's AI Mistakenly Banned Chess Channel over Chess Language Misinterpretation

YouTube's AI Mistakenly Banned Chess Channel over Chess Language Misinterpretation

Jun 2020 · 6 reports
Loading...
Images of Black People Labeled as Gorillas

Images of Black People Labeled as Gorillas

Jun 2015 · 24 reports
Loading...
OpenAI’s GPT-3 Reported as Unviable in Medical Tasks by Healthcare Firm

OpenAI’s GPT-3 Reported as Unviable in Medical Tasks by Healthcare Firm

Oct 2020 · 1 report
Previous IncidentNext Incident

Similar Incidents

Selected by our editors

Meta AI App Reportedly Publishes Personal Chats Without Users Fully Realizing

Apr 2025 · 3 reports
By textual similarity

Did our AI mess up? Flag the unrelated incidents

Loading...
YouTube's AI Mistakenly Banned Chess Channel over Chess Language Misinterpretation

YouTube's AI Mistakenly Banned Chess Channel over Chess Language Misinterpretation

Jun 2020 · 6 reports
Loading...
Images of Black People Labeled as Gorillas

Images of Black People Labeled as Gorillas

Jun 2015 · 24 reports
Loading...
OpenAI’s GPT-3 Reported as Unviable in Medical Tasks by Healthcare Firm

OpenAI’s GPT-3 Reported as Unviable in Medical Tasks by Healthcare Firm

Oct 2020 · 1 report

Research

  • Defining an “AI Incident”
  • Defining an “AI Incident Response”
  • Database Roadmap
  • Related Work
  • Download Complete Database

Project and Community

  • About
  • Contact and Follow
  • Apps and Summaries
  • Editor’s Guide

Incidents

  • All Incidents in List Form
  • Flagged Incidents
  • Submission Queue
  • Classifications View
  • Taxonomies

2024 - AI Incident Database

  • Terms of use
  • Privacy Policy
  • Open twitterOpen githubOpen rssOpen facebookOpen linkedin
  • b9764d4