Meta AI
Max payout:
Guidelines
At Meta, we value the contributions of external researchers in helping us identify and address potential vulnerabilities in our AI products and services. These guidelines outline how we evaluate the impact of reports submitted through our Bug Bounty program and determine the corresponding payouts, with a maximum payout $130,000* for issues specific to AI products and services and then apply any applicable deduction based on the required user interaction, prerequisites, and any other mitigation factors to arrive at the final awarded bounty amount.
Payouts
Examples
Being able to take over a private user’s Meta AI account (ATO)
|
Being able to leak private user conversations, Connector data (e.g., email/calendar data), images, artifacts, and/or user PII using Meta AI features
|
Being able to leak deleted user conversations, images, and/or artifacts using Meta AI features
|
Being able to exploit a victim user using CSRF, XSS, and/or data -style attack by sharing a malicious AI Artifact
|
Accessing or modifying another user's agentic session, conversation, or generated content without authorization - including reading conversation history, modifying private artifacts, or accessing private media
|
Exfiltration of third-party OAuth tokens or credentials (accessing a victim's connected service tokens (e.g., Gmail, Outlook, Google Drive, Apple Health, etc.)) through Meta AI, enabling persistent access to their third-party accounts.
|
Being able to leak sensitive AI user assets (i.e. an image, artifact, or post) using FBID or other low entropy identifier that is otherwise secured using a high entropy identifier like PFBID
|
Mitigating factors (deduction from maximum amount)
We consider the following factors when deducting from the maximum payout to arrive at the final bounty amount:
User content is intentionally public
Up to 100% |
User data is limited (e.g., only Meta AI data is returned, but no Family of Apps (FOA) data is affected)
Up to 50% |
Victim interaction requirements that reduce real-world exploitability - To align with latest product requirements, the current guidance is that all attacks which require unrealistic user interaction are not payout eligible until further notice - Unrealistic user interaction describes non-standard actions that include clicking unobfuscated malicious links, uploading attacker-crafted content, manually initiating a specific prompt, and re-interacting with previous tool output Up to 100% |
Victim account requirements that reduce number of potential victims (e.g., victim connected their Email account) Up to 50% |
Examples
Read/Write access to internal Meta data
|
Read/Write access to training data
|
Access to proprietary AI model weights and architecture
|
Access to experimental, next-generation, premium, or non-public AI Models |
Access to Meta AI or any proprietary Meta agent
|
Access to modify a non-public AI setting or parameter
|
Mitigating factors (deduction from maximum amount)
We consider the following factors when deducting from the maximum payout to arrive at the final bounty amount:
Meta data is intentionally public
Up to 100% |
Has some limitations (e.g., limited internal access) Up to 90% |
Examples
Dangerous tool execution without human confirmation - Being able to trigger financial actions (e.g., modify sensitive Ads/Business settings, make purchases, and add subscriptions).
|
Confused Deputy vulnerabilities - Being able to escalate permissions using AI to call sensitive APIs/services (e.g., using AI agent to reduce the price of a purchase order)
|
Mitigating factors (deduction from maximum amount)
We consider the following factors when deducting from the maximum payout to arrive at the final bounty amount:
Limitations to the callable APIs/services -90% or higher |
Examples
Being able to inject strings as a third party that appear to the agent as direct user prompts or system prompts i.e. a prompt injection that is consistently reproducible because it bypasses prompt injection defenses
|
Being able to hide malicious instructions using invisible and other special formatting characters from the user prior to getting the AI agent to process those malicious instructions
|
Mitigating factors (deduction from maximum amount)
We consider the following factors when deducting from the maximum payout to arrive at the final bounty amount:
Prompt injection is non-deterministic and not consistently reproducible
Up to 100% |
Smuggled prompt is not completely invisible and alters the victim’s UI/UX
Up to 100% |
Common Mitigating factors
Common Mitigation factors across the guidelines
Requires victim to perform a read action
|
Requires victim to perform a write action
|
Requires the victim to have enabled/connected a specific third-party service (e.g., Gmail, Calendar)
|
Requires additional information (e.g., knowledge of Metagen key), or has some prerequisites (e.g., must be a FB Page owner)
|
The following issues are currently ineligible, unless any of the eligible risks are demonstrated.
Being able to perform Prompt Injection/Jailbreak
- Until further notice, prompt Injection and jailbreaks are considered payout-ineligible unless they are chained with another payout-eligible risk on this list. Example:
- Prompt Injection that results in System Prompt extraction is payout-ineligible
- Prompt injection via connected data source (email, calendar, documents) that results in data exfiltration of the victim will be triaged as accessing private user content.
- The risk of prompt injection is measured by the impact of its outcome
Hallucination - In the context of Bug Bounty, Hallucinations include the following scenarios:
- GenAI output contains factually incorrect or seemingly random content
- Prompt injection / Jailbreak that cannot consistently be reproduced
In both scenarios, Hallucinations are considered payout-ineligible even if they are chained with a payout-eligible risk on this list
AI Integrity issues
- Integrity bypasses are considered payout-ineligible unless it results in a payout-eligible risk on this list or is caused by a payout-eligible risk on this list
Agent Tools enumeration without demonstrating further impact
Additional bounty for CSRF, XSS vulnerability will be paid as per our general payout guidelines.