I also double-checked the session token received from the REST API and Android Client. It is the same. Even after I changed my password.
These are definitely potential security issues. Anyone who has stolen a mobile device, a hacker can get a session token if the session is not encrypted and the security of user data is permanently compromised.
How a hacker could use a session token from any client forever. You will never know when a hacker will do evil. I am seriously concerned about the problem. Hope someone will contact him.
PS: Hi Mario, I registered a problem on the platform for developers of Facebook.
https://developers.facebook.com/bugs/309490399239393/
Hope someone tracks it and resolves it in the end.
source share