Blog | G5 Cyber Security

Indecent disclosure: Gay dating app left private images, data exposed to Web (Updated)

Security researcher Oliver Hough found a security hole in Jack’d dating app. Photos were uploaded to an AWS S3 bucket accessible over an unsecured Web connection, identified by a sequential number. Location data and other metadata about users was accessible via the application’s API. Hough also found that by changing the sequential number associated with his image, he could essentially scroll through images uploaded in the same timeframe as his own. The bug is fixed in a February 7 update, but the fix comes more than three months after Ars Technica contacted the company.”]

Source: https://arstechnica.com/information-technology/2019/02/indecent-disclosure-gay-dating-app-left-private-exposed-to-web/

Exit mobile version