Close Menu
Innovation Village | Technology, Product Reviews, Business
    Facebook X (Twitter) Instagram
    Sunday, May 18
    • About us
      • Authors
    • Contact us
    • Privacy policy
    • Terms of use
    • Advertise
    • Newsletter
    • Post a Job
    • Partners
    Facebook X (Twitter) LinkedIn YouTube WhatsApp
    Innovation Village | Technology, Product Reviews, Business
    • Home
    • Innovation
      • Products
      • Technology
      • Internet of Things
    • Business
      • Agritech
      • Fintech
      • Healthtech
      • Investments
        • Cryptocurrency
      • People
      • Startups
      • Women In Tech
    • Media
      • Entertainment
      • Gaming
    • Reviews
      • Gadgets
      • Apps
      • How To
    • Giveaways
    • Jobs
    Innovation Village | Technology, Product Reviews, Business
    You are at:Home»Apps»Dating App Grindr Security Flaw Allowed Hackers to Take Over Users’ Accounts
    Dating App Grindr

    Dating App Grindr Security Flaw Allowed Hackers to Take Over Users’ Accounts

    0
    By Tapiwa Matthew Mutisi on October 7, 2020 Apps, Cybercrime, Report, Security, Technology

    A major security flaw affecting the dating app Grindr allowed attackers to potentially take over any user’s account, provided they knew or could guess the email address associated with it. Security researcher Troy Hunt – who runs Have I Been Pwned? – published a report detailing the vulnerability, which he was alerted to by security researcher Wassime Bouimadaghene.

    The vulnerability enabled a complete account takeover using a trivial attack which only requires that the attacker enter a valid email address for the targeted account. It has since been fixed, but Hunt noted the nature of the access to sensitive information potentially provided to attackers was concerning.

    All the attacker needed to do to begin this attack was to visit the Grindr password reset page, where they would enter the email address of the target’s account. After the captcha is completed on this page, a notification is shown stating that a password reset link has been emailed to the user.

    However, inspecting the response using browser development tools revealed the password reset token, which could be pasted into the reset URL without needing to access the password reset email. The attacker could then reset the user’s password and use the new credentials to log in to the user’s Grindr account through the mobile app.

    The information which was exposed through this vulnerability include fields such as age, weight, ethnicity, HIV status, and more. Private messages and other sensitive information such as images would also be exposed due to the complete takeover of the victim’s account by an attacker.

    Grindr has since fixed this vulnerability, stating they believe the issue was addressed before it could be exploited by attackers. “As part of our commitment to improving the safety and security of our service, we are partnering with a leading security firm to simplify and improve the ability for security researchers to report issues such as these,” the company told TechCrunch.

    “In addition, we will soon announce a new bug bounty program to provide additional incentives for researchers to assist us in keeping our service secure going forward.”

    Related

    Cyber Security Cyber-attack Dating App Grindr Mobile Apps Security breach Troy Hunt
    Share. Facebook Twitter Pinterest LinkedIn Email
    Tapiwa Matthew Mutisi
    • Facebook
    • X (Twitter)
    • LinkedIn

    Tapiwa Matthew Mutisi has been covering blockchain technology, intelligent technologies, cryptocurrency, cybersecurity, telecommunications technology, sustainability, autonomous vehicles, and other topics for Innovation Village since 2017. In the years since, he has published over 4,000 articles — a mix of breaking news, reviews, helpful how-tos, industry analysis, and more. | Open DM on Twitter @TapiwaMutisi

    Related Posts

    Android Boosts Safety with Smarter Scams Protection and Find Hub

    Microsoft Lays Off 3% of Workforce Amid Rising AI Investment Costs

    JAMB UTME Crisis: 1.5 Million Low Scores, 8,000 Complaints — But Who’s Protecting the Students?

    Leave A Reply Cancel Reply

    You must be logged in to post a comment.

    Copyright ©, 2013-2024 Innovation-Village.com. All Rights Reserved

    Type above and press Enter to search. Press Esc to cancel.