If that doesn't prove that FB's developers aren't thinking about security, I don't know what would. Nobody who is in a culture of protecting security would even consider building this.
However, someone had to implement the backend for listing out those photos, and they clearly didn't think of access control, so there's at least something fishy here…
If there's a goof here, it's that the framework they've built apparently doesn't make the privacy controls mandatory. Developers have to remember to "turn them on" by calling an access control predicate or whatnot. That's bad. That's dumb. But it's not malicious.