Visualização de leitura

Meta to Pay Up to $18B Over Teen Social Media Use

Meta will pay up to $18B and cap teen Facebook and Instagram use at two hours daily after nearly all US states sued over child safety.

Meta will pay up to $18 billion over the next decade and impose real usage limits on teenagers using Facebook and Instagram, settling claims that the company deliberately designed its platforms to addict children. The deal ended a federal trial mid-stream, right as Instagram head Adam Mosseri had begun testifying and Mark Zuckerberg was expected to take the stand next.

The timing made sense given the huge potential penalties. Four states, California, Colorado, Kentucky, and New Jersey, were seeking up to $200 billion in damages. Before the trial, Meta said they could demand as much as $1.4 trillion. Against those figures, the $18 billion settlement looks relatively small, although it still equals about three to four months of Meta’s profits.

The most important part of the deal is what Meta agreed to change. Teenagers will be limited to two hours a day on Facebook and Instagram. Meta will also block access between midnight and 6 a.m. unless a parent gives permission, and it will turn off most push notifications during school hours.

“The focus of this case was to protect our kids,” Colorado Attorney General Phil Weiser said in a statement reported by Reuters. “The relief we are getting in this settlement is very meaningful and well beyond what any court has ordered or is likely to order.””

What the settlement leaves unchanged matters too. Meta does not have to stop using personalized recommendations or targeted ads for teenagers. It also does not have to remove specific types of content that researchers have linked to negative effects, such as posts that can make users feel worse about their bodies. A two-hour limit is still a meaningful restriction, but Meta can continue trying to maximize engagement during those two hours.

The deal also creates an interesting financial incentive. Of the roughly $16.7 billion going to 47 states, Washington D.C., Puerto Rico and other territories, about $12.7 billion is guaranteed. The remaining $5 billion depends on whether Snapchat, TikTok and YouTube introduce similar protections for teenagers. This gives Meta a financial reason to push its competitors to adopt the same rules, which is why the company reportedly plans to use newspaper ads to encourage TikTok and YouTube to follow suit.

Separately, Wednesday’s settlement also resolved lingering state privacy claims tied to the Cambridge Analytica scandal, with Meta agreeing to pay $459 million on top of everything else. That’s an old wound getting stitched up alongside a much newer one, in the same afternoon.

Not every state joined the settlement. New Mexico stayed out after winning a $567 million public nuisance ruling against Meta earlier this month, on top of a separate $375 million jury verdict. Attorney General Raul Torrez said the settlement didn’t include some changes his case had pushed for, including stronger protection against adults targeting children and a ban on sexualized AI chatbot interactions with minors. Still, he called the deal a step forward.

Florida rejected the settlement altogether. Attorney General James Uthmeier said the payouts amount to “peanuts” compared with the harm caused and said Florida would take Meta to trial instead.

Legal experts already see the settlement as a possible model for future cases. Northwestern law professor James Speta said Meta and other tech companies faced growing pressure to change anyway, from Congress, state lawmakers and the public. That makes the settlement more than a single case: it could set a standard that courts and regulators use when judging other platforms.

Thousands of similar lawsuits from individuals, school districts and municipalities are still moving through courts across the U.S. If those cases follow the same pattern, we haven’t seen the last of these headlines.

“Today, we are announcing an agreement with a bipartisan group of 52 attorneys general across US states, territories, and the District of Columbia, building on our longstanding efforts to empower parents and support teens.” reads the statement published by Meta.

“Over the years, we have consistently partnered with parents and experts — listening, learning, and building. That’s why we launched Teen Accounts in 2024, to bring automatic protections to teens, and more control for parents.”

The agreement aims to push YouTube, TikTok and other platforms to adopt similar protections for teenagers.

“While this is an important step, the fact is that teens move fluidly between dozens of apps a day. All platforms should empower parents and support teens by putting the same measures in place, because we know that when teens are restricted on one app, they simply move to another.” concludes Meta. “For meaningful progress to happen, we urge TikTok and YouTube to join us and state attorneys general in adopting this new standard, to ensure teens use social media in a healthy and responsible way.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Facebook)

US Navy tells sailors and their families: scrub your social media, enemies are watching

The US Navy has told its entire workforce of 340,000 active-duty personnel, 58,000 reservists, and 210,000 civilian employees to clean up their social media profiles, because adversaries might be using them to determine who they are, where they live, and when they may not be at home. Read more in my article on the Hot for Security blog.

TikTok Settles U.S. Child Privacy Case for $400 Million

TikTok will pay $400 million to settle U.S. claims that it violated child privacy laws by collecting data from users under 13.

The U.S. Department of Justice announced that TikTok will pay $400 million to settle a 2024 lawsuit over children’s privacy.

“Today, the Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated entities (TikTok) resolving litigation concerning compliance with the Children’s Online Privacy Protection Act and its implementing regulations (COPPA).” reads the press release published by DoJ. “Under the settlement, TikTok will pay $300 million immediately and an additional $100 million upon entry of an order vacating a prior consent decree entered against TikTok’s predecessor, Musical.ly. The settlement represents one of the largest recoveries ever obtained in a COPPA case.”

TikTok will pay $300 million immediately and another $100 million after a court order removes an earlier consent decree involving Musical.ly. The 2024 case, brought by the DoJ and FTC, accused TikTok of knowingly allowing children under 13 to create accounts and illegally collecting data from children using Kids Mode.

Since the Justice Department filed its lawsuit against TikTok in 2024, the company has made major changes to its ownership, management, compliance, and privacy practices. It has also introduced stronger safeguards for younger users, improved age controls, and expanded parental oversight.

The DOJ said these measures have advanced the goals of its case and strengthened protections for millions of U.S. families. The settlement reflects a focus on practical results, securing a significant recovery while recognizing TikTok’s compliance improvements. The case was filed in California and handled by the DOJ’s Civil Division following a referral from the FTC.

“This settlement is a major victory for American children and parents,” said Associate Attorney General Stanley E. Woodward Jr. “The Department’s priority is ensuring that children are protected online and that companies entrusted with their personal information meet their legal obligations. This resolution secures a substantial recovery while reinforcing the protections that families expect and deserve.”

TikTok has faced regulatory scrutiny over children’s privacy before. In September 2023, Ireland’s Data Protection Commission fined the company €345 million for breaching the GDPR through its handling of children’s personal data.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, privacy)

Meta Ordered to Pay $567 Million Over Child Safety Failures in New Mexico Case

Meta was ordered to pay $567M after a judge ruled its platforms harmed children, bringing New Mexico penalties to $942M.

Meta ‘s child-safety legal bill just got another half-billion dollars heavier. A New Mexico state judge ruled that company’s platforms constitute a “public nuisance,” the BBC reports, ordering $567 million into a fund meant to address harm the company caused to children. Combined with an earlier $375 million penalty from the same case, Meta now owes New Mexico $942 million total.

“Judge Bryan Biedscheid said the social media giant is a “public nuisance” akin to air pollution and that it must put the money in a fund aimed at reducing future harms.Thursday’s ruling is in addition to $375m in fines Meta was already ordered to pay in the case, for a total of $942m.” BBC reports. “Judge Biedscheid compared Meta to a factory, with advertising and content as its product and “the psychological harm and sexual exploitation of children to be the pollution that must be abated”.”

Judge Bryan Biedscheid didn’t hold back on the framing. He compared Meta to a factory, with advertising and content as its output and the psychological harm and sexual exploitation of children as the pollution that output produces. It’s the kind of comparison a judge doesn’t reach for lightly, and according to CNN, it’s the first time any social media company has been legally labeled a public nuisance.

“The court found that “just as noxious pollution produced by the factory can harm the common public right to reasonably clean air, the harmful effects of Meta’s platforms on children do not stay contained by its platforms and, instead, migrate to the internet as a whole and, perhaps most concerning, to the real world and create a common, societal burden on and harm to the affected children and their families and schools, as well as hospitals and law enforcement.”” CNN reports.

The case traces back to a 2023 lawsuit from state attorneys general, and it unfolded in two phases. A March jury verdict already found Meta had repeatedly violated New Mexico’s Unfair Practices Act, largely because its recommendation algorithms steered young users toward harmful content and predatory contacts. This second phase, decided by the judge alone rather than a jury, existed specifically to answer one question: did that harm rise to the level of a public nuisance affecting the broader community.

According to CNBC’s reporting, Biedscheid’s written ruling didn’t pull punches on causation either.

“Expert testimony supports a causal link between social media and the youth mental health crisis in New Mexico,” the ruling states, closing off Meta’s usual argument that any correlation is just correlation.

Most of the money has a specific destination. $420 million goes toward direct treatment, funding clinical and behavioral health programs for young people already affected. The remainder covers prevention training for teachers and healthcare workers, plus broader awareness efforts, all running over roughly the next five years, according to PBS.

Cash isn’t the only thing Meta has to hand over. The judge ordered a list of concrete platform changes: no recommending accounts of users under 18 to adults, no adults messaging minors, a ban on sending or receiving nudity for underage accounts, and elimination of “like” counts for teen users. Push notifications get blocked overnight and during school hours on weekdays, and total monthly usage for minors gets capped at 90 hours across Instagram and Facebook combined, roughly three hours a day.

Meta’s response was predictable and brief. A company spokesperson said Meta disagrees with the ruling and will appeal, adding that the company has worked hard to keep people safe and remains confident in its record protecting teens online.

“We disagree with the ruling and will appeal.” a company spokesman told BBC. “We work hard to keep people safe on our platforms and have been transparent about the challenges of identifying and removing bad actors and harmful content,” he added.

“We remain confident in our record of protecting teens online and will continue to defend ourselves against claims that misrepresent the facts.”

That’s the same basic line the company used after the March verdict, and it’s likely to stay the company line through however many appeals this takes.

New Mexico is far from the only front in this fight. Nearly three dozen state attorneys general are pursuing a separate case against Meta over child privacy violations, with another major trial starting next week in California, and Meta already lost a Los Angeles case earlier this year that found it could be held liable for building deliberately addictive platforms. Add in the EU’s ongoing preliminary findings against Meta over underage users on Instagram and Facebook, and the pattern stops looking like isolated lawsuits and starts looking like a coordinated reckoning across multiple jurisdictions at once.

Former Twitter executive Bruce Daisley put the number in context on BBC Radio 4, calling it “a drop in the ocean” against Meta’s finances; the company posted $61 billion in quarterly revenue this year, up 28% from the year before. The fine is real money by any normal measure. Whether it’s real money by Meta’s measure is a different question entirely, and it’s the one regulators worldwide are now racing to answer with policy rather than just penalties.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Meta)

Bad Epoll Flaw Gives Attackers Root Access on Linux and Android

Bad Epoll (CVE-2026-46242) lets local attackers gain root on Linux and Android. The flaw was missed by AI but found by a security researcher.

A newly disclosed Linux kernel vulnerability, named Bad Epoll (CVE-2026-46242), allows a local attacker with no special privileges to gain full root access on affected Linux systems and Android devices. Security updates are already available, and users are urged to install them as soon as possible.

The flaw affects the Linux kernel’s epoll subsystem, a core feature used by servers, browsers, and countless applications to efficiently manage multiple network connections and file events. Because epoll is fundamental to Linux, there is no practical workaround other than patching vulnerable systems.

Bad Epoll is a classic use-after-free vulnerability, which occurs when a program continues to use a piece of memory after it has already been released (“freed”).

Two kernel threads attempt to release the same internal object simultaneously. One frees the memory while the other continues using it, creating a brief opportunity to corrupt kernel memory and escalate privileges to root.

Bad Epoll

“Two of epoll’s close paths run at the same time and collide. One frees an object while the other is still writing into it, and that is the use-after-free (UAF).” continues the advisory. “The race window, and how the exploit drives it. The exploit uses four epoll objects grouped into two pairs. One pair triggers the race, while the other becomes the victim. From there, the exploit turns the 8-byte UAF write into a UAF on a file object, and uses a cross-cache attack to fully control the file’s contents. Turning the bug into an arbitrary kernel memory read through /proc/self/fdinfo. With that control, the exploit gains an arbitrary read of kernel memory through /proc/self/fdinfo. Finally, it hijacks control flow and executes a ROP chain to gain a root shell.”

Although exploiting the flaw requires hitting a timing window only six CPU instructions wide, researcher Jaeyoung Chung developed a reliable proof-of-concept that reportedly succeeds in about 99% of attempts on tested systems. According to the researcher, the exploit can even be launched from Chrome’s renderer sandbox, making it particularly dangerous, and could also impact Android devices.

“Bad Epoll (CVE-2026-46242) is a race-condition use-after-free in the Linux kernel’s epoll subsystem. This bug lets an unprivileged process become root, not only on Linux desktops and servers but also on Android devices.” reads an advisory published by Chung.

One of the most interesting aspects of the vulnerability is its connection to AI-assisted vulnerability research. Bad Epoll originates from the same section of kernel code where Anthropic’s Mythos model previously identified another privilege escalation flaw, tracked as CVE-2026-43074. The AI detected the first bug, but missed this closely related vulnerability, which was later discovered manually.

“A single commit in 2023 introduced two separate race conditions into the epoll code, only about 2,500 lines in all. Both turned out to be critical bugs that can lead to privilege escalation.

The first was found by Anthropic’s Mythos and reported as CVE-2026-43074. That result is impressive on its own, because kernel race bugs are known to be hard to find. It showed a frontier AI model’s ability to find race bugs. An independent researcher later submitted a 1-day exploit for it to kernelCTF.” continunes the advisory. “The other race is Bad Epoll, which Mythos missed.”

Chung believes the miss is understandable. The race condition is extremely difficult to reason about because the vulnerable execution path exists for only a tiny fraction of a second. In addition, once the first flaw was patched, Bad Epoll no longer generated obvious warnings through KASAN, Linux’s memory error detection system, making it even harder to spot.

The good news is that there is currently no evidence that Bad Epoll has been exploited in the wild. The only public exploit is the proof-of-concept released through Google’s kernelCTF program. An Android exploit is reportedly still under development.

Bad Epoll

The flaw affects Linux kernels based on version 6.4 and later, unless they already include the upstream fix. Older long-term support kernels based on Linux 6.1, including some Android devices such as the Pixel 8, are not vulnerable because the problematic code was introduced after those versions branched.

Bad Epoll joins a growing list of high-profile Linux privilege escalation vulnerabilities recently disclosed, including Copy Fail, Dirty Frag, Fragnesia, and DirtyClone. While many of these newer vulnerabilities are deterministic and relatively easy to exploit, Bad Epoll belongs to the older class of race-condition bugs, which are significantly harder to discover, exploit, and patch.

The case also highlights both the promise and the current limitations of AI in vulnerability research. Models such as Mythos have already demonstrated they can identify complex kernel flaws and even uncover long-standing vulnerabilities in projects like FreeBSD.

At the same time, Bad Epoll shows that highly subtle race conditions can still escape even state-of-the-art AI systems. For now, human expertise remains essential, particularly when vulnerabilities depend on tiny timing windows and complex concurrent execution paths.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Bad Epoll)

❌