Facebook exposed private lists of users' friends to app developers without their knowledge until two weeks ago, despite claiming to have blocked this functionality three years ago.
The loophole allowed apps to collect the friend lists of anybody who had installed the app, exposing their names and profile photos. Facebook quietly switched the "taggable friends" interface off on April 4, burying the announcement among a series of other privacy measures.
The revelations are the latest privacy blow to the social network, which has come under fire for enabling app makers to pool personal information of millions of unknowing users.
The data were later sold to companies such as Cambridge Analytica, and allegedly employed by Donald Trump and Ted Cruz's presidential campaigns.
In 2014, Facebook was made aware that an app developed by a Cambridge University academic had been scooping up personal details on not only those who installed it but all of their friends, culminating in what Facebook estimated to be a database of 87 million people.