Succesful hack allows attacker to access private photos, ability to delete victim's photos and to edit comments and also the ability to post new photos.
Hacker explained that there are two ways to hack Instagram accounts using OAuth, first via
Hijack Instagram accounts using the Instagram OAuth or Hijack
Instagram accounts using the Facebook OAuth Dialog.
During his bug hunting Nir found loopholes in Instagram’s security parameters i.e redirect_uri , that allows attacker to pass the access token to his own domain with mx as suffix i.e code straight to breaksec.com.mx.