
Meta has patched a critical vulnerability in its AI support tool after reports suggested attackers could exploit the system to take over Instagram accounts. According to TechCrunch, attackers were able to use Meta's AI support chatbot to change email addresses associated with targeted Instagram accounts and subsequently reset passwords, potentially bypassing protections such as two-factor authentication. The vulnerability involved the AI-powered support assistant introduced in December to help users recover access to locked Facebook and Instagram accounts more quickly. Meta spokesperson Andy Stone confirmed on X that the vulnerability had been fixed, though the company has not disclosed how many Instagram accounts were affected or how long the vulnerability existed.
The attack method required attackers to use VPN services to make their location appear similar to that of the targeted account holder, as reported by TechCrunch. They would initiate a conversation with Meta's AI Support Assistant and request that a new email address be added to the victim's Instagram account. The chatbot would send a verification code to the email address supplied by the attacker, after which attackers were presented with a password reset option. Several users publicly reported losing access to their Instagram accounts, with security researcher Jane Wong confirming her account was taken over and experiencing multiple password reset attempts before losing access. The Instagram account associated with US Space Force Chief Master Sergeant John Bentivegna was also reportedly affected.
Meta is confronting multiple legal battles across the United States, with New Mexico opening a bench trial to determine whether Facebook, Instagram, and WhatsApp constitute a public nuisance. In March, a jury had ordered Meta to pay $375 million in civil penalties for misleading the public about platform safety, and prosecutors are now seeking $3.7 billion in remedies including increased age verification, curbs on algorithmic recommendations, and an end to autoplay and infinite scroll features. Separately, Texas Attorney General Ken Paxton filed suits against both Netflix and Meta under the Texas Deceptive Trade Practices Act, with the Meta suit alleging the company misled users by claiming WhatsApp messages were protected by end-to-end encryption while maintaining internal systems allowing employee access to private communications. Meta has stated it may shut down its platforms in New Mexico if ordered to comply, while the company announced AI-powered age assurance measures to detect underage users and automatically place them in age-appropriate accounts.
Meta's Model Capability Initiative (MCI) has sparked an intense employee revolt since its quiet introduction in April 2025. The program, originally framed as a tool to improve AI capabilities, has evolved into what workers are calling a "data extraction factory" that captures far more information than Meta has publicly acknowledged. According to internal accounts, MCI captures not just clicks and mouse movements, but also code changes, computer sleep/wake patterns, and URLs copied to clipboards, creating a surveillance system that extends well beyond the company's initial disclosures.
Meta AI, the company's AI assistant embedded across Facebook, Instagram, WhatsApp, and Messenger, reached approximately 1 billion monthly active users in 2025, making it the fastest AI assistant in history to reach that scale. As reported by multiple sources, Meta's AI strategy has delivered measurable results, with the company's Family Daily Active People metric reaching 3.35 billion in December 2024, representing 5% year-on-year growth. Meta's advantage lies in distribution, as Meta AI is embedded in applications that 3.35 billion people already use daily, providing unmatched access to users compared to competing AI assistants.