Earlier quoted context omitted.
This isn't correct, it's not the only way. A Facebook vulnerability is less valuable than a browser 0-day and could similarly leak credentials. In fact, Facebook has had numerous authentication blunders in the past. [1] One of them was a zero-click mechanism very recently. [2] Facebook's security team is a joke, or worse -- they're muzzled by product teams and forced to do their bidding. [3] [1] https://threatpost.co…
You're right. But when there's an exploited vulnerability Facebook logs everyone out and then posts a blog post about it, as show by the 2018 hack you linked to. That hasn't happened here. I don't really consider 3 years ago to be very recent. I think that 3rd link is arguably not a vulnerability. If you intentionally want people to be able to look up future friends by email address, then that's basically the desired…
Ask yourself why Facebook doesn't just make available a spreadsheet of all names associated with which emails on the platform. It's because it's private information.
Why doesn't Facebook's security team do anything? Either they're incompetent, or they're being muzzled by product.
Additionally, Facebook's privacy policy explicitly says that they don't share your private information that you have chosen to set private. That's an egregious lie.