It feels like a privilege escalation exploit: at a certain point the authority chain jumped from a random picture provided who knows where/when to a link in the chain that should be reliable enough to blindly trust in this subject.