A new security and privacy issue has been found inside the Facebook app.
The Facebook app on iOS is using the device's camera in the background for some people. Spotted by Twitter users Joshua Maddux and Daryl Lasafin, the bug appears when you're viewing a photo, like a profile image, and then swipe down to dismiss it. In the video below, you can see some carpet that the phone's camera is being pointed at on the left side of the screen.
Found a @facebook #security & #privacy issue. When the app is open it actively uses the camera. I found a bug in the app that lets you see the camera open behind your feed. Note that I had the camera pointed at the carpet. pic.twitter.com/B8b9oE1nbl
— Joshua Maddux (@JoshuaMaddux) November 10, 2019
Maddux says that he was able to recreate the issue on five different iPhones running iOS 13.2.2. I haven't been able to recreate the bug on my iPhone, but the folks at The Next Web say they ran into the issue on iOS 13.2.2 but not on iOS 13.1.3. You'll need to have granted the Facebook app access to your camera to see the issue appear.
This issue doesn't appear to be affecting Android.
If you've got an iPhone, you can block Facebook's access to your camera by launching the Settings app and selecting "Privacy" followed by "Camera".
Facebook hasn't issued a statement on this bug, so there's not clear exactly what's happening or when it might be fixed. Seeing your device's camera active in an app when you're not actually using it is a bit unsettling, though, and could raise some serious privacy concerns for a lot of people. Stay tuned and we'll update you with more info on this issue as it becomes available.
Facebook app on iOS 13.2.2 opens my phone’s rear camera when I open a profile photo swipe down to return (look at the little slit on the left of the video). Is this an app bug or an iOS bug?? @facebook @AppleSupport pic.twitter.com/WlhSXZulqx
— Daryl Lasafin (@dzlasafin) November 10, 2019
UPDATE: Guy Rosen, VP of Integrity at Facebook, says that this camera issue is a bug and that it's been confirmed that the camera didn't capture anything because it was in preview mode and that nothing was uploaded to Facebook. An update to the Facebook app for iOS is now rolling out that fixes this bug.