Meta may occasionally find critical security bugs or vulnerabilities in third-party code and systems, including open source software. When that happens, our priority is to see these issues promptly fixed, while making sure that people impacted are informed so that they can protect themselves by deploying a patch or updating their systems.
That sounds simple and clear-cut. However, vulnerability disclosure is anything but simple. Here is what motivated our policy:
Vulnerability Disclosure Policy
In a nutshell, Meta will contact the appropriate responsible party and inform them as quickly as reasonably possible of a security vulnerability we’ve found. We expect the third party to respond within 21 days to let us know how the issue is being mitigated to protect the impacted people. If we don’t hear back within 21 days after reporting, Meta reserves the right to disclose the vulnerability. If within 90 days after reporting there is no fix or update indicating the issue is being addressed in a reasonable manner, Meta will disclose the vulnerability.
That said, we will adhere to the vulnerability disclosure steps and the proposed timelines whenever reasonably possible, but we can envision scenarios where there might be deviations. If Meta determines that disclosing a security vulnerability in third party code or systems sooner serves to benefit the public or the potentially impacted people, we reserve the right to do so.
Here are some details.
Reporting
Mitigation & Timeline
Disclosure
Additional Disclosure Considerations
Finally, this policy refers to what Meta does when we find an issue in third party code. If you believe you have found a security vulnerability in Meta technologies such as Facebook or Instagram, we encourage you to report it through our Bug Bounty Program.
META QUEST
Meta Quest: *Parents:* Important guidance & safety warnings for children’s use here. Using Meta Quest requires an account and is subject to requirements that include a minimum age of 10 (requirements may vary by country). See meta.com/quest/terms and the parent’s info page at meta.com/quest/parent-info. Certain apps, games and experiences may be suitable for a more mature audience. META QUEST FEATURES, FUNCTIONALITY, AND CONTENT NOTICE: Features, functionality and content are subject to change or withdrawal at any time, may not be available in all areas or languages or may be restricted; may require enabled software or service activation, and additional terms, conditions and/or charges may apply.
META QUEST IMPORTANT SAFETY NOTICE https://www.meta.com/quest/quest-2-facial-interface-recall/.
Financing Options. You may be offered financing options for your Meta purchases. Learn more here.
***Based on the graphic performance of the Qualcomm Snapdragon XR2 Gen 2 vs XR2 Gen 1 on Meta Quest 2
RAY-BAN META
Meta AI and voice commands only in select countries and languages. Please check local availability. Meta account and Meta View App required. For ages 13+ only. Requires compatible phone with Android or iOS operating system plus wireless internet access. Features, functionality and content are subject to change or withdrawal at any time. Additional account registration, terms and fees may apply. Software updates may be required. Performance may vary based on user location, device battery, temperature, internet connectivity and interference from other devices, plus other factors. User must comply with all applicable local laws and regulations, especially relating to privacy. May interfere with personal medical devices. Check manufacturer Safety & Warranty Guide and FAQs for more product information, including battery life.
OPTIONAL FINANCING
©2025 Meta.