Unremovable Tags In Facebook Page Reviews

Max Pasqua
Dec 14, 2018 · 1 min read

Facebook pages have a feature to leave reviews on them. When making a review a malicious user could tag a victim and it would render the tag unremovable. Upon trying to remove it would give the victim an error. The impact behind this is that the victim is permanently stuck tagged. Attackers could leverage this with massive spam posts or embarrassing information against the victim and he will not be able to remove himself from the post.

Proof of Concept

1) Browse to the page that you want the tag to be stuck on (Preferably owned by the attacker so the owner of the page wont remove the post)

2) Create a review and tag the victim

3) The victim will now no longer be able to remove the tag



Submitted- October 13th, 2018

Triaged- October 18th, 2018

Bounty Awarded($500)- December 14th, 2018

