Facebook security hole allows anyone to view private New Year's Midnight Delivery messages and photos (update: fixed)

hamburger story

Facebook recently launched Midnight Deliveries, a special feature that allows users to send messages that will be delivered as the clock strikes midnight on New Year's Eve. In a surprising security slip-up, first detailed in a blog post by IT student Jack Jenkins, the company has made the URLs for these messages public. The Verge has confirmed that the flaw allows those logged into Facebook to view other people's messages and photos, and even delete them. By simply changing the digits in a string of numbers at the end of message URLs, Facebook users can gain access to other people's communications — though users are unable to target specific individuals by exploiting the security flaw.

While many of these New Year's greetings may not include sensitive material, it's obviously a serious issue considering how easy it is to view other people's private messages. We've notified Facebook of the issue and will update you as soon as we receive additional information from the company. In the meantime, you may want to wait for a fix before using the feature, or remove messages you've already created that may contain sensitive private information.

Update: Facebook's special New Year's messaging site has been taken down for maintenance. The company has not responded to our inquiry, but it looks like it received the message; we'll let you know as soon as we can confirm the issue has been resolved.

Update 2: A Facebook spokesperson tells The Verge that "we are working on a fix for this issue now, and in the interim we have disabled this app on the Facebook Stories site to ensure that no messages can be accessed."

Update 3: The app is once again available.

Thanks, Jackthewelshman!

The Verge
Log In Sign Up

Log In Sign Up

Please choose a new Verge username and password

As part of the new Verge launch, prior users will need to choose a permanent username, along with a new password.

Your username will be used to login to Verge going forward.

I already have a Vox Media account!

Verify Vox Media account

Please login to your Vox Media account. This account will be linked to your previously existing Eater account.

Please choose a new Verge username and password

As part of the new Verge launch, prior MT authors will need to choose a new username and password.

Your username will be used to login to Verge going forward.

Forgot password?

We'll email you a reset link.

If you signed up using a 3rd party account like Facebook or Twitter, please login with it instead.

Forgot password?

Try another email?

Almost done,

By becoming a registered user, you are also agreeing to our Terms and confirming that you have read our Privacy Policy.



Choose an available username to complete sign up.

In order to provide our users with a better overall experience, we ask for more information from Facebook when using it to login so that we can learn more about our audience and provide you with the best possible experience. We do not store specific user data and the sharing of it is not required to login with Facebook.