It's disappointing that Meta chose not to fix this and chose not to reward this researcher with a bug bounty.
I reported a similar issue to Google early this year and they declined the submission because it "can only result from social engineering" and "we think that addressing it would not make our users significantly less vulnerable". I won't mention the details here but Google Search sometimes rewrite URLs in such way that an attacker can spoof the actual URL. My advice is to never trust URLs displayed by websites and app…
I think I saw something like this a while ago, with some fake KeePass website maybe.