genai
SECURITY LAB
IncidentsSensitive information disclosure

Meta AI's 'Discover' Feed Aired Private Chats in Public

Medium severityJune 2025LLM02: Sensitive Information Disclosure
Status: Reported by Business Insider / TechCrunch (Jun 2025); a share flow many users misread. Distinct from the separate Jul 2025 IDOR bug
On this page

People typed private things into a chatbot, hit a button they misread, and posted them to a public feed.

WhenJune 2025
TargetMeta AI standalone app (Discover feed)
VendorMeta
Surfaced byBusiness Insider / TechCrunch reporting
CauseA confusing share flow; sharing framed as opt-in
Attack flow
  1. 1A user has a private conversation in the Meta AI app
  2. 2They tap a 'share' flow that many read as private
  3. 3The prompt — text, audio or image — appears in a public 'Discover' feed

What happened

In June 2025, users of Meta's standalone AI app discovered that private conversations — text, audio and images — were appearing in a public 'Discover' feed. A share flow that many people read as private actually published their prompts for anyone to see. Meta characterised sharing as opt-in rather than a bug, but the confusing design led people to broadcast deeply personal content.

How it happened

There was no attacker and no breach. A 'share' action, insufficiently distinguished from a private save, moved sensitive conversations into a public, browsable feed — a consent/design failure rather than an exploit.

Root cause

A privacy-hostile flow: the consequence of 'share' (public and browsable) was not obvious at the moment of choosing it.

What a review would have caught

A privacy/UX review asking 'what is the worst thing a confused user could unintentionally publish, and is the consequence obvious?' flags a feed like this before launch.

How to prevent it

  • Default to private; make 'public' a high-friction, clearly-labelled action.
  • Show exactly what will be shared, and where, at the point of choice.
  • Provide easy revocation when someone changes their mind.

FAQ

Was this a hack?

No — no attacker and no breach. It's a design/consent failure: a 'share' flow that many users read as private posted their conversations to a public Discover feed.

Why include a UX problem in a security database?

Confidentiality can fail through interface design as easily as through an exploit. LLM02 covers sensitive information being disclosed — and a misread share button disclosed exactly that, at scale.

How is it prevented?

Default to private, make the consequence of 'share' unmistakable at the moment of choosing, and treat public publication of AI conversations as a high-friction, clearly-labelled action.

No live replay yet
This incident is documented for reference — a hands-on lab that recreates this specific attack isn’t available yet. Browse the full database for incidents you can replay.