Impersonation

Max payout:

$65k*

Guidelines

These guidelines outline our process for assessing the security impact of vulnerabilities that allow an attacker to post media, comment, or delete objects as another user. We cap the maximum base payout for an impersonation vulnerability at $65,000* and then apply any applicable deduction based on the required user interaction, prerequisites, and any other mitigation factors to arrive at the final awarded bounty amount.

Payouts

Being able to post a media as someone else which can be viewed by followers and friends
up to
$65k*

Maximum payouts

Being able to post a media as someone else which can be viewed by followers and friends
up to
$65k*
Being able to make comments as another user
up to
$10k*
Being able to delete comments as another user
up to
$10k*
Being able to delete the media of another user
up to
$10k*
Being able to pin comments as another user
up to
$5k*

Mitigating factors (deduction from maximum amount)

We consider the following factors when deducting from the maximum payout to arrive at the final bounty amount:

Media posted as another user is not easily discoverable (for example, not shown in the feed) and requires user activity to be shown
-75% or higher
Requires the attacker to spend money to boost content
-50% or higher
Partial or ambiguous impersonation attempts
Note: In some cases, could be also 500$ or informative.
-90% or higher
Requires action from the victim
Note: In some cases, could be also 500$ or informative.
-90% or higher
Important

Please test against your own test users when trying to view or test, and abide by our responsible research and disclosure policy.