Meta AI

Max payout:

$130k*

Guidelines

At Meta, we value the contributions of external researchers in helping us identify and address potential vulnerabilities in our AI products and services. These guidelines outline how we evaluate the impact of reports submitted through our Bug Bounty program and determine the corresponding payouts, with a maximum payout $130,000* for issues specific to AI products and services and then apply any applicable deduction based on the required user interaction, prerequisites, and any other mitigation factors to arrive at the final awarded bounty amount.

Payouts

Being able to access private user content
up to
$130k*

Examples

Being able to take over a private user’s Meta AI account (ATO)
Being able to leak private user conversations, Connector data (e.g., email/calendar data), images, artifacts, and/or user PII using Meta AI features
Being able to leak deleted user conversations, images, and/or artifacts using Meta AI features
Being able to exploit a victim user using CSRF, XSS, and/or data -style attack by sharing a malicious AI Artifact
Accessing or modifying another user's agentic session, conversation, or generated content without authorization - including reading conversation history, modifying private artifacts, or accessing private media
Exfiltration of third-party OAuth tokens or credentials (accessing a victim's connected service tokens (e.g., Gmail, Outlook, Google Drive, Apple Health, etc.)) through Meta AI, enabling persistent access to their third-party accounts.
Being able to leak sensitive AI user assets (i.e. an image, artifact, or post) using FBID or other low entropy identifier that is otherwise secured using a high entropy identifier like PFBID

Mitigating factors (deduction from maximum amount)

We consider the following factors when deducting from the maximum payout to arrive at the final bounty amount:

User content is intentionally public
Up to 100%
User data is limited (e.g., only Meta AI data is returned, but no Family of Apps (FOA) data is affected)
Up to 50%
Victim interaction requirements that reduce real-world exploitability

- To align with latest product requirements, the current guidance is that all attacks which require unrealistic user interaction are not payout eligible until further notice
- Unrealistic user interaction describes non-standard actions that include clicking unobfuscated malicious links, uploading attacker-crafted content, manually initiating a specific prompt, and re-interacting with previous tool output
Up to 100%
Victim account requirements that reduce number of potential victims (e.g., victim connected their Email account)
Up to 50%
Being able to access sensitive internal Meta data
up to
$30k*

Examples

Read/Write access to internal Meta data
Read/Write access to training data
Access to proprietary AI model weights and architecture
Access to experimental, next-generation, premium, or non-public AI Models
Access to Meta AI or any proprietary Meta agent
Access to modify a non-public AI setting or parameter

Mitigating factors (deduction from maximum amount)

We consider the following factors when deducting from the maximum payout to arrive at the final bounty amount:

Meta data is intentionally public
Up to 100%
Has some limitations (e.g., limited internal access)
Up to 90%
Being able to trigger privileged/dangerous actions and modify sensitive data
up to
$20k*

Examples

Dangerous tool execution without human confirmation - Being able to trigger financial actions (e.g., modify sensitive Ads/Business settings, make purchases, and add subscriptions).
Confused Deputy vulnerabilities - Being able to escalate permissions using AI to call sensitive APIs/services (e.g., using AI agent to reduce the price of a purchase order)

Mitigating factors (deduction from maximum amount)

We consider the following factors when deducting from the maximum payout to arrive at the final bounty amount:

Limitations to the callable APIs/services
-90% or higher
Prompt smuggling
up to
$5k*

Examples

Being able to inject strings as a third party that appear to the agent as direct user prompts or system prompts i.e. a prompt injection that is consistently reproducible because it bypasses prompt injection defenses
Being able to hide malicious instructions using invisible and other special formatting characters from the user prior to getting the AI agent to process those malicious instructions

Mitigating factors (deduction from maximum amount)

We consider the following factors when deducting from the maximum payout to arrive at the final bounty amount:

Prompt injection is non-deterministic and not consistently reproducible
Up to 100%
Smuggled prompt is not completely invisible and alters the victim’s UI/UX
Up to 100%

Common Mitigating factors

Common Mitigation factors across the guidelines

Requires victim to perform a read action
Requires victim to perform a write action
Requires the victim to have enabled/connected a specific third-party service (e.g., Gmail, Calendar)
Requires additional information (e.g., knowledge of Metagen key), or has some prerequisites (e.g., must be a FB Page owner)
Ineligible for the payout

The following issues are currently ineligible, unless any of the eligible risks are demonstrated.

  • Being able to perform Prompt Injection/Jailbreak

    - Until further notice, prompt Injection and jailbreaks are considered payout-ineligible unless they are chained with another payout-eligible risk on this list. Example:

    - Prompt Injection that results in System Prompt extraction is payout-ineligible

    - Prompt injection via connected data source (email, calendar, documents) that results in data exfiltration of the victim will be triaged as accessing private user content.

    - The risk of prompt injection is measured by the impact of its outcome

  • Hallucination - In the context of Bug Bounty, Hallucinations include the following scenarios:

    - GenAI output contains factually incorrect or seemingly random content

    - Prompt injection / Jailbreak that cannot consistently be reproduced

    In both scenarios, Hallucinations are considered payout-ineligible even if they are chained with a payout-eligible risk on this list

  • AI Integrity issues

    - Integrity bypasses are considered payout-ineligible unless it results in a payout-eligible risk on this list or is caused by a payout-eligible risk on this list

  • Agent Tools enumeration without demonstrating further impact

Notes

Additional bounty for CSRF, XSS vulnerability will be paid as per our general payout guidelines.