The model "exploited a security vulnerability in a third-party service, in a manner similar to previously reported instances with other companies," Meta said in a statement