Using what sounds like a simple trick, a user can also access their friends’ latest pending friend-requests and which friends they share in common. That’s a lot of potentially sensitive information...
...The irony is that the exploit is enabled by they way that Facebook lets you preview your own privacy settings. In other words, a privacy feature contains a flaw that lets others view private information if they are aware of the exploit.
TechCrunch reported the issue to Facebook and the company pulled the live chat feature off line for what was described as "maintenance."
This YouTube video provides a glimpse of the severity of the problem:
On the site, Facebook offered a ho-hum response to the issue:
Chat is unavailable as we work quickly to fix a bug reported to us. It should return to normal soon. Because of the bug, people could view friends’ chat messages and friend requests for a limited amount of time if they manipulated the “preview my profile” feature in a specific way. We’ve fixed that issue and took down Chat as soon as we became aware of it. We apologize for the inconvenience.