Independent security researcher Christian Lopez Martin has identified a cross-site reference forgery (CSRF) vulnerability in Instagram that could have been leveraged to gain access to users photos and information by making their private profiles public.
The expert found that the service didnt use any mechanism to prevent CSRF attacks. This allowed him to create a simple CSRF exploit.
The security hole was first reported to Facebook on August 22, 2013. Fa…