Jaipur:Neeraj Sharma, a 20-year-old, second-year student of BCA, was awarded a monetary reward worth Rs 38 lakhs for pointing out a bug in the social media platform Instagram's reels section. As informed by Neeraj, through the vulnerability that he was able to find, the attacker could have changed the reel thumbnails of any Instagram user by knowing just the media ID of the reel, irrespective of how strong the password of the account holder was.
Neeraj, a resident of the Sanganer area in Jaipur, is currently a student of the Poddar International College. An avid internet surfer, he started looking for bugs in the Instagram app in December 2021. He says he initially tested a few things on Instagram Ads but did not find any bugs there, so he started hunting on the Instagram reels section.
After spending some time with the target, he came to a point where users can edit their reels' cover photos, also known as a thumbnail. For testing, he changed his reel's thumbnail and was surprised to discover the bug. "I was surprised as I did not expect such a vulnerability in a subsidiary of a giant like META. I immediately reported it to Meta Security Team," Neeraj wrote in one of his blogs.