Security expert Jack Whitton reported a critical XSS vulnerability to Facebook that could be exploited by hackers to take over users Facebook accounts. Facebook fixed the problem in just 6 hours. Facebook rewarded the expert $7,500 the expert for the flaw under its bounty program. The researcher wrote embedded an XSS payload into a PNG images IDAT chunk, which differently from Exif and iTXt data, were not removed by Facebook by removing them from the CDN. If the user were logged in, the malicious script could allow impersonating the victim and access his data.”]
Source: http://securityaffairs.co/wordpress/44112/hacking/facebook-xss-takover-accounts.html

