The problem, which Facebook says it has fixed, is the latest privacy scandal for the world's largest social media company.
The company said on Thursday that the bug automatically suggested that users make new posts public, even if they had previously restricted to "friends only" or another private setting.
Erin Egan, Facebook's chief privacy officer, says the bug did not affect past posts.
She added that Facebook is notifying users who posted publicly during the time the bug was active to review their posts.
The news follows a recent furore over Facebook's sharing of user data with device makers, including China's Huawei.