Privacy Glitch in Snapchat Web Exposed Notification Leak After Logout


Affected Feature

Snapchat Web's notification system. When logged into Snapchat on a browser, you get notifications for incoming snaps and video calls.

How to Reproduce

  1. Log into Snapchat Web on Chrome
  2. Change your Snapchat password from the mobile app (this forces logout on all sessions)
  3. Verify the web session logged out properly
  4. Notifications for snaps and video calls still keep coming to the browser

Even though the session is terminated, the notification channel stays active. I recorded a video showing notifications arriving in real-time on a logged-out session.

Company Response

Reported through Snapchat's bug bounty program. Initially marked "Informative" because they thought it required physical access and wasn't a real threat. I pushed back explaining users expect full logout means no notifications either. They eventually agreed and fixed it - notifications now properly stop when you log out of Snapchat Web.


Comments

Popular posts from this blog

When an AI Search Engine Forgot Who It Was: A Bug Report That Changed Perplexity AI’s Identity

Understanding Android’s One-Time Permissions and Their Privacy Implications

Your Android Phone's Dirty Little Secret - Gemini