home
blog
resume
contact
blog
Reading Anyone's Private Meta AI Conversations — Without Authentication
The sendMessageStream GraphQL mutation on meta.ai doesn't check whether you own a conversation. One API call to read anyone's full chat history.
March 2026
$5,000
CVSS 7.5