Description
An Instagram Endpoint was leaking WhatsApp numbers linked with Instagram Accounts
Impact
This bug could've been used to view the WhatsApp number linked with Instagram Accounts despite the setting set to be hidden.
Proof of concept
POST https://i.instagram.com/api/v1/users/[userID]/info/
Timeline
24 June 2021 - Report Sent
30 June 2021 - Reply From Security Personnel: Need More Info
28 July 2021 - Triaged
06 August 2021 - Fixed By Facebook
19 August 2021 - $1000 Bounty Rewarded By Facebook