A bug in the app shares private photos with everyone on the web

May 27, 2013 14:26 GMT  ·  By

Facebook has to run a fine line between getting people to share more and respecting their privacy. Sometimes it manages to strike a balance, sometimes it doesn't.

Either way, the company gets a lot of scrutiny over privacy issues, as it should.

So it definitely doesn't need to be actively leaking out private information. But, as page admins using the Page Manager app for Android are discovering, a serious flaw does just that, leaking private photos publicly.

The Page Manager app enables admins to contact fans via private messages, or to reply to inquiries or any other issues.

These messages should normally end up in the private message inbox. However, if admins attach a photo to the message, the message and the photo are published to the page's timeline for everyone to see.

This, obviously, can create some awkward or even dangerous situations for those involved. And, of course, that's certainly not the intended behavior.

Android Police found out about the bug and tested it, disclosing it in full after attempts at contacting Facebook failed.

Only after the disclosure did the company reply by saying that it was looking into the issue and that a fix should be out soon. Since the problem seems to be on the server side, this likely won't require an app update.

If it does, Facebook can at least move fast and get the update on people's phones and tablets within hours rather than weeks in the iTunes App Store.