If you believe your account has been compromised by another person or a virus, To help keep your Facebook account secure, Facebook will take you through a few steps to change your password and make sure any recent changes to your account came from you.
Link — https://www.facebook.com/hacked

POC Video-

/hacked feature added an unconfirmed email address on my account.

Impact — This could have allowed malicious users to take over any emails not confirmed on Facebook and this could potentially allow a malicious individual to access third party apps which rely on Facebook account verification of email.

Timeline -

Submitted- November 15th, 2018

Bounty - January 5, 2019

Sameer Rao

Security Researcher

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store