A security researcher uncovered a Meta vulnerability that could have exposed private support records. The company fixed the flaw and awarded a $78,000 bug bounty for responsible disclosure.