Researchers: 3rd-party JavaScript trackers embedded on sites using Login With Facebook can grab Facebook user data; abusive scripts found on 434 of top 1M sites
Facebook confirms to TechCrunch that it's investigating a security research report that shows Facebook user data can be grabbed …
Context & Ripple Effects
This report lands mid-2018, when Facebook's data-handling practices were under sustained researcher scrutiny — and it widens the attack surface from rogue apps to ordinary web pages. The finding that third-party JavaScript on 434 of the top 1 million sites can pull Facebook user data through Login With Facebook means any publisher embedding both a login widget and a tracker becomes an unwitting leak vector.
The pattern held long after this story: researchers later documented Facebook Analytics summary reports leaking to outside testers, and argued Facebook had known for years about the exploit class behind the contact-importer scraping of 533M users' data. Embedded-script access like this sits upstream of those incidents — it is how data leaves the platform before any app-level audit applies.
First-order effects
- Operators of the 434 flagged sites face immediate cleanup decisions: strip the abusive scripts or risk losing Facebook integrations and user trust, while Facebook investigates which trackers accessed what data.
- Publishers using Login With Facebook must now treat their own third-party tag stack as part of their data-exposure surface, since the login widget grants script-level reach into user identity data.
Second-order effects
- Advertisers and brands buying against Facebook's logged-in identity graph face a credibility problem: if embedded scripts can siphon user data, the value proposition of authenticated targeting weakens at exactly the moment regulators are watching.
- Facebook is pushed toward auditing and constraining its embed ecosystem — the same researcher-driven disclosure cycle that surfaced the Analytics leak and the Cultura Colectiva exposed 540M-record database shows external parties, not internal review, are doing the discovery.
Third-order effects
- If the pattern holds, platform data governance shifts from policing app developers to policing every page that embeds platform code — permission boundaries drawn around scripts rather than apps, enforced by auditors and regulators rather than terms of service.
- Repeated researcher findings that Facebook knew of exploit classes in advance strengthen the case for mandatory external security audits of platform APIs, making disclosure-by-researcher a standing feature of the industry rather than an exception.
The trend: Platform data leakage is expanding from misbehaving apps to the embedded-script supply chain, with independent researchers — not the platforms — setting the pace of discovery.