Fixed : Register any email address on Facebook Account.

Sameer Rao
1 min readMar 5, 2019

If you believe your account has been compromised by another person or a virus, To help keep your Facebook account secure, Facebook will take you through a few steps to change your password and make sure any recent changes to your account came from you.
Link — https://www.facebook.com/hacked

POC Video-

/hacked feature added an unconfirmed email address on my account.

Impact — This could have allowed malicious users to take over any emails not confirmed on Facebook and this could potentially allow a malicious individual to access third party apps which rely on Facebook account verification of email.

Timeline -

Submitted- November 15th, 2018

Bounty - January 5, 2019

--

--