Privacy Glitch in Snapchat Web Exposed Notification Leak After Logout
Affected Feature
Snapchat Web's notification system. When logged into Snapchat on a browser, you get notifications for incoming snaps and video calls.
How to Reproduce
- Log into Snapchat Web on Chrome
- Change your Snapchat password from the mobile app (this forces logout on all sessions)
- Verify the web session logged out properly
- Notifications for snaps and video calls still keep coming to the browser
Even though the session is terminated, the notification channel stays active. I recorded a video showing notifications arriving in real-time on a logged-out session.
Company Response
Reported through Snapchat's bug bounty program. Initially marked "Informative" because they thought it required physical access and wasn't a real threat. I pushed back explaining users expect full logout means no notifications either. They eventually agreed and fixed it - notifications now properly stop when you log out of Snapchat Web.

Comments
Post a Comment