Facebook has patched a serious vulnerability that could have allowed attackers to gain access to user account data. The vulnerability would have allowed a potential attacker to steal sensitive pieces of information known as OAuth access tokens. Facebook runs a bug bounty program through which it pays monetary rewards to security researchers who find and responsibly report vulnerabilities affecting the site. The researcher claims to have found a vulnerability on Facebook’s websites for mobile and touch-enabled devices that stemmed from improper sanitization of URL paths. Facebook has no evidence that users were affected by this bug.”]

