The issue was, that even without the person accepting the friend request, the "is now friends with" status message of this person was updated. Thus, it was possible to track a person's friends without their permission.
SecurityPitfalls.org is a community project that collects situations where security fails. It's primarily for educational purpose, as source for discussions and presentations and for fun. If you have related material you want to share with others, just send in your photos, stories or movies to incoming {at} securitypitfalls.org.