Shop with Confidence – Curated Selections, Great Prices, and 100% Trust at BuyTrustedFinds.

A Lovense safety flaw could also be letting individuals take over accounts and not using a password

Intercourse toy firm Lovense is leaking the e-mail addresses of its app customers and permitting account takeovers with out asking for a password, based on a safety researcher. As reported by , BobDaHacker, who describes themself as an moral hacker dedicated to exposing and reporting safety vulnerabilities, printed an wherein they accuse Lovense of failing to repair a severe bug it was first made conscious of in 2023.

In line with the hacker (and later verified by TechCrunch), Lovense permits any username to be became their e mail tackle with the fitting know-how, a flaw they initially found after muting somebody on the app. With their entry to Lovense’s API, they had been in a position to receive the emails related to any public username in lower than a second when working the modified request course of by an automatic script. They famous that the weak nature of those accounts is “particularly unhealthy for cam fashions” who use the Lovense platform for work, and should share their usernames for these functions.

The researcher additionally realized that with a person’s e mail tackle (both one you already know or one obtained utilizing the aforementioned disclosure bug), they may generate auth tokens that allowed them to take over the related account and not using a password. This allegedly labored for the Lovense Chrome Extension and Lovense Join app, in addition to the corporate’s Cam101 and StreamMaster software program — and even admin accounts.

BobDaHacker mentioned they initially reported the bugs to Lovense with help from the intercourse tech hacking challenge in March 2025, and acquired $3,000 in complete for flagging them by way of the HackerOne safety platform. After a collection of interactions with Lovense representatives, they had been informed in early June that the account takeover bug had been mounted through the earlier month, which the researcher claims just isn’t true. Concerning the e-mail disclosure flaw, Lovense mentioned in a printed by BobDaHacker that it may take as much as 14 months to repair the difficulty, as a sooner one-month repair would “require forcing all customers to improve instantly,” which it mentioned would “disrupt assist for legacy variations.”

The researcher went on to say that they had been contacted by a Twitter person who claimed to have discovered the identical account takeover bug way back to 2023, and had been informed shortly after reporting it to Lovense that the bug had been resolved, which wasn’t the case. They mentioned a patch finally mounted their technique, which used an HTTP endpoint to transform a username into an e mail tackle, however that it wasn’t rolled out till early 2025. BobDaHacker mentioned that they had requested remark from Lovense however on the time of writing had not acquired one.

This isn’t the primary time Lovense customers have stumbled upon privacy concern bugs. In 2017, a Redditor that the Lovense app, which permits customers to manage their intercourse toys remotely, was recording audio with out their consent and saving it to their telephone. A commenter on the Reddit , who claimed to be a Lovense consultant, referred to as the recordings a “minor software program bug” that affected the Android model of the app and mentioned on the time that it had been mounted in an replace.

Trending Merchandise

0
Add to compare
- 42% HP 230 Wireless Mouse and Keyboard ...
Original price was: $43.23.Current price is: $24.99.

HP 230 Wireless Mouse and Keyboard ...

0
Add to compare
0
Add to compare
- 15% LG 27MP400-B 27 Inch Monitor Full H...
Original price was: $129.99.Current price is: $109.99.

LG 27MP400-B 27 Inch Monitor Full H...

0
Add to compare
- 18% LG 34WP65C-B UltraWide Computer Mon...
Original price was: $399.99.Current price is: $329.00.

LG 34WP65C-B UltraWide Computer Mon...

0
Add to compare
- 43% SAMSUNG 25″ Odyssey G4 Series...
Original price was: $349.99.Current price is: $199.99.

SAMSUNG 25″ Odyssey G4 Series...

0
Add to compare
- 50% GIM Micro ATX PC Case with 2 Temper...
Original price was: $79.99.Current price is: $39.99.

GIM Micro ATX PC Case with 2 Temper...

0
Add to compare
- 20% LG UltraGear QHD 27-Inch Gaming Mon...
Original price was: $299.99.Current price is: $240.20.

LG UltraGear QHD 27-Inch Gaming Mon...

0
Add to compare
- 42% Philips 221V8LB 22 inch Class Thin ...
Original price was: $120.38.Current price is: $69.99.

Philips 221V8LB 22 inch Class Thin ...

0
Add to compare
- 36% Antec AX Series AX61 Elite, High-Ai...
Original price was: $101.32.Current price is: $64.95.

Antec AX Series AX61 Elite, High-Ai...

0
Add to compare
.

We will be happy to hear your thoughts

Leave a reply

BuyTrustedFinds
Logo
Register New Account
Compare items
  • Total (0)
Compare
0
Shopping cart