LIVE · cybersecurity feed
Live wire
ai

Meta AI builds detailed profiles of children from years of family posts

A mother says Meta AI pieced together names, birth details, photos, and location information about her young daughters from years of family posts.

zeroday.news ·

Meta AI, the company's artificial intelligence assistant, has been observed creating detailed profiles of children by aggregating information from years of family posts on Facebook and Instagram. The issue came to light in early September when a mother, Kalie Robins, posted a video of her young daughter on Facebook. Meta AI then prompted her with the question, "Who is the child passenger?"

Upon clicking the prompt, Robins reported that Meta AI began compiling extensive information on both of her children. This included their names, birth dates, and videos. The system also retrieved a picture of her newborn daughter that her mother had posted years prior, as well as a photo Robins herself had deleted from her account a long time ago.

The AI's data collection extended beyond the children. It subsequently asked, "Where does Kalie Robins live?" When she clicked this prompt, Meta AI reportedly sifted through years of her posts, including old content hinting at past residences and newer posts connecting her to her current home, ultimately attempting to pinpoint her exact location. Robins expressed shock and outrage that Facebook would construct such detailed profiles from disparate historical posts without her explicit consent or awareness.

Meta AI, which launched in April 2024 and is integrated across Facebook, Instagram, WhatsApp, and Messenger, is designed to answer questions, generate images, and assist with information retrieval. In response to Robins' experience, Meta acknowledged that "The feature never should have prompted the individual with questions like that." The company stated that the feature "missed the mark" and that the underlying issue causing Meta AI to suggest questions about personal topics had been fixed.

A Meta spokesperson clarified that the AI only surfaced information that the user asking the question could already access. However, this explanation does not account for the reported retrieval of a photo Robins claimed to have deleted years ago.

This incident follows previous privacy concerns related to Meta AI. In June of the prior year, users reportedly shared conversations publicly without realizing it. A subsequent bug in July could have allowed individuals to view private Meta AI chats by guessing user IDs. Late last year, Meta also began using Meta AI conversations to target users with advertisements.

The incident highlights the extensive data social media platforms can accumulate on individuals, including minors, from years of user-generated content. Users are advised to consider the implications of posting identifiable images and videos of children on social media platforms, as such content can be aggregated and used to construct detailed profiles. Robins has indicated her intention to remove all identifiable pictures and videos of her children from her accounts and will ask friends to do the same to prevent their content from being harvested by Meta AI.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

malware

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

malware

Iranian spies hit Windows machines with Chosen Brick data-stealing malware

'Enemies of the regime' on notice

patch

Before You Patch. Why Patch Reliability Matters for Confident Deployment

Executive Summary Microsoft’s September 2026 security updates, KB5124008 and KB5124012, have been linked to USB audio failures on some Windows systems, highlighting the operational risk that can accompany security patching. Qualys TruRisk Eliminate classified both updates as Low Reliability, signaling the need for additional validation before production deployment. Patch Reliability helps IT and s