The latest Facebook security blunder involves photos from 6.8 million users. The company shared in an update on its developer page today that a bug allowed third-parties to see photos from Facebook users who had uploaded, but chose to not post them to the social media service.

As reported by TechCrunch, Facebook detailed in its post today that the flaw occurred between September 13-25.

There were several scenarios in which the API bug affected users:

At this time, Facebook believes the flaw affected up to 1,500 third-party apps from almost 900 developers, used by up to 6.8 million Facebook users.

Facebook says that is is working on building a tool for developers to be able to tell which users were affected by the flaw. It will also be letting users know if they were impacted with Facebook alerts. The company recommends users to check out what permissions third-party apps have for their Facebook accounts.

As for an apology, Facebook offered a super short one toward the end of the post: “We’re sorry this happened.”

  • Facebook hack update: no evidence of any access to third-party apps
  • Facebook details what information hackers accessed from 30 millions users
  • Facebook admits cyber attack may have exposed info from 50 million accounts to hackers
  • Facebook latest: all users may have had some data exposed, messages monitored (for good reasons), more
  • Cambridge Analytica filing for bankruptcy after Facebook scandal, but may re-emerge
  • Sensitive internal Facebook emails published by UK parliament detail use of its free iOS ‘spyware’ VPN and more