The Facebook vulnerability resides in validating the contents of the files posted through links and Unvalidated re-directions. The Vulnerability was identified by Rajwinder Singh, he posted a malicious office macro file that contains reverse shell payload in the Facebook post section. He created a Payload with msfvenom and obfuscated VBA Scripts with Chrw() function that returns a Unicode character, if in case Unicode is not supported by the system it acts as Chr function which returns ASCII or ANSI character.”]
Source: https://gbhackers.com/facebook-vulnerability-allow-attackers/

