> A hidden mechanism exists within the code base that allows Meta to bypass any user-facing controls, enabling them to access personal data even if you’ve set your privacy settings to the most restrictive levels.
While concerning, this is worded so vaguely that it could conceivably apply to any code that changes at runtime. You could be referring to anything from an iOS/Android CVE to a poorly-programmed Javascript library. Without serious details it's hard to say what you're talking about, and therefore it's hard to judge the threat you're whistleblowing.