Facebook says that between Sept. 13 and Sept. 25 a photo API bug gave user-approved apps access to photos that were uploaded but never shared by ~6.8M users
Reset the “days since the last Facebook privacy scandal” counter, as a Facebook has just revealed a Photo API bug gave app developers …
Context & Ripple Effects
This is the third major Facebook data exposure disclosed in 2018 alone: June's bug that flipped sharing settings to public for 14M users, September's access-token theft affecting ~50M accounts, and now a photo API that handed user-approved apps photos people uploaded but never actually shared. The pattern is consistent — the failure point is not hacking but Facebook's own permission plumbing between what users approved and what apps received.
The disclosure lands while Facebook is still expanding its bug bounty program to cover third-party apps and exposed access tokens, an acknowledgment that its developer ecosystem is where its privacy risk concentrates. That makes this photo API slip less an outlier than another instance of the same boundary problem.
First-order effects
- Roughly 6.8M users learn that apps they had approved could pull photos they never chose to share, forcing Facebook to notify affected people and audit which developers actually accessed the unshared images.
- App developers holding that photo data now face deletion demands and heightened review from Facebook, on top of the access-token exposure rules it began enforcing after the September breach.
Second-order effects
- Every new disclosure tightens the screws on the developer ecosystem: the following year Facebook found ~100 app developers may have improperly accessed Groups member data even after API restrictions were announced (Groups API improper access), showing audits beget more audits.
- Users rationally respond by approving fewer apps, shrinking the reach of the entire third-party app economy built on Facebook login and Graph API permissions.
Third-order effects
- If the pattern holds, the structural endpoint is a locked-down platform: Facebook keeps narrowing what APIs expose, converting an open developer ecosystem into a tightly gated one where data access is exception-based rather than default.
- Repeated self-disclosed bugs also hand regulators a documented track record of permission-boundary failures, strengthening the case for external oversight of how platforms govern developer data access.
The trend: Facebook's 2018 run of API and settings bugs marks the platform's shift from an open developer ecosystem toward progressively restricted, audited data access.