In 2020, Facebook announced that it had fixed a critical vulnerability in its password reset system. The bug allowed attackers to steal access tokens, which could be used to hijack user accounts. This vulnerability was particularly concerning, as it could have been exploited by attackers to gain access to sensitive user information.