Close Menu
OnlyPlanz –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Greedy ruthlessness has had a great PR campaign in business – but these toy shop owners show a better way | Zoe Williams

    August 11, 2025

    John Oliver on Ice’s crackdown: ‘Trying to drive up arrests at all costs’ | John Oliver

    August 11, 2025

    AXA IM in talks to take stake in Telefónica Spanish fibre venture

    August 11, 2025
    Facebook X (Twitter) Instagram
    Trending
    • Greedy ruthlessness has had a great PR campaign in business – but these toy shop owners show a better way | Zoe Williams
    • John Oliver on Ice’s crackdown: ‘Trying to drive up arrests at all costs’ | John Oliver
    • AXA IM in talks to take stake in Telefónica Spanish fibre venture
    • Bright Tangerine Halo Universal Base Kit
    • Another Day, Another Merger: Biglaw Firm Scoops Up Midsize Firm Gutted By Departures
    • 18 Essential Digital Marketing Tools to Boost Your Business Growth
    • Ford To Build New $30K Midsize Electric Pickup In Louisville Kentucky
    • EasyJet captain suspended after getting ‘drunk and naked’ in hotel
    Facebook X (Twitter) Instagram Pinterest Vimeo
    OnlyPlanz –OnlyPlanz –
    • Home
    • Marketing
    • Branding
    • Modeling
    • Video Creation
    • Editing Tips
    • Content
    • Engagement
    • More
      • Tools
      • Earnings
      • Legal
      • Monetization
    OnlyPlanz –
    Home»Tools»A Lovense security flaw may be letting people take over accounts without a password
    Tools

    A Lovense security flaw may be letting people take over accounts without a password

    onlyplanz_80y6mtBy onlyplanz_80y6mtJuly 29, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    A Lovense security flaw may be letting people take over accounts without a password
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Intercourse toy firm Lovense is leaking the e-mail addresses of its app customers and permitting account takeovers with out asking for a password, based on a safety researcher. As reported by TechCrunch, BobDaHacker, who describes themself as an moral hacker dedicated to exposing and reporting safety vulnerabilities, revealed an in depth report wherein they accuse Lovense of failing to repair a critical bug it was first made conscious of in 2023.In accordance with the hacker (and later verified by TechCrunch), Lovense permits any username to be become their e mail tackle with the suitable know-how, a flaw they initially found after muting somebody on the app. With their entry to Lovense’s API, they had been capable of receive the emails related to any public username in lower than a second when operating the modified request course of via an automatic script. They famous that the weak nature of those accounts is “particularly unhealthy for cam fashions” who use the Lovense platform for work, and should share their usernames for these functions.The researcher additionally realized that with a person’s e mail tackle (both one you already know or one obtained utilizing the aforementioned disclosure bug), they might generate auth tokens that allowed them to take over the related account with out a password. This allegedly labored for the Lovense Chrome Extension and Lovense Join app, in addition to the corporate’s Cam101 and StreamMaster software program — and even admin accounts.BobDaHacker stated they initially reported the bugs to Lovense with help from the intercourse tech hacking venture The Web Of Dongs in March 2025, and obtained $3,000 in whole for flagging them through the HackerOne safety platform. After a collection of interactions with Lovense representatives, they had been instructed in early June that the account takeover bug had been fastened throughout the earlier month, which the researcher claims will not be true. Concerning the e-mail disclosure flaw, Lovense stated in a press release printed by BobDaHacker that it might take as much as 14 months to repair the problem, as a quicker one-month repair would “require forcing all customers to improve instantly,” which it stated would “disrupt assist for legacy variations.”The researcher went on to say that they had been contacted by a Twitter person who claimed to have discovered the identical account takeover bug way back to 2023, and had been instructed shortly after reporting it to Lovense that the bug had been resolved, which wasn’t the case. They stated a patch ultimately fastened their methodology, which used an HTTP endpoint to transform a username into an e mail tackle, however that it wasn’t rolled out till early 2025. BobDaHacker stated that they had requested remark from Lovense however on the time of writing had not obtained one.This isn’t the primary time Lovense customers have stumbled upon privateness concern bugs. In 2017, a Redditor found that the Lovense app, which permits customers to manage their intercourse toys remotely, was recording audio with out their consent and saving it to their cellphone. A commenter on the Reddit publish, who claimed to be a Lovense consultant, known as the recordings a “minor software program bug” that affected the Android model of the app and stated on the time that it had been fastened in an replace.

    accounts flaw letting Lovense password people security
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleSarah Pound’s easy focaccia with four simple toppings – recipe | Australian food and drink
    Next Article IMF upgrades global growth forecast as tariffs ease
    onlyplanz_80y6mt
    • Website

    Related Posts

    Tools

    The Rise of a New AI Superpower

    August 11, 2025
    Tools

    US Judiciary System says it was hacked, is taking steps to strengthen cybersecurity

    August 11, 2025
    Tools

    Windows 10 support is ending. Here’s what you need to do now

    August 11, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    5 Steps for Leading a Team You’ve Inherited

    June 18, 20255 Views

    A Pro-Russia Disinformation Campaign Is Using Free AI Tools to Fuel a ‘Content Explosion’

    July 1, 20253 Views

    Meera Sodha’s vegan recipe for Thai-style tossed walnut and tempeh noodles | Noodles

    June 28, 20253 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    Modeling

    Greedy ruthlessness has had a great PR campaign in business – but these toy shop owners show a better way | Zoe Williams

    onlyplanz_80y6mtAugust 11, 2025
    Content

    John Oliver on Ice’s crackdown: ‘Trying to drive up arrests at all costs’ | John Oliver

    onlyplanz_80y6mtAugust 11, 2025
    Earnings

    AXA IM in talks to take stake in Telefónica Spanish fibre venture

    onlyplanz_80y6mtAugust 11, 2025

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    SLR reform is happening. Does it matter?

    June 18, 20250 Views

    Panthers in awe of Brad Marchand’s ‘will to win’ in Cup run

    June 18, 20250 Views

    DOJ Offers Divestiture Remedy in Lawsuit Opposing Merger of Defense Companies

    June 18, 20250 Views
    Our Picks

    Greedy ruthlessness has had a great PR campaign in business – but these toy shop owners show a better way | Zoe Williams

    August 11, 2025

    John Oliver on Ice’s crackdown: ‘Trying to drive up arrests at all costs’ | John Oliver

    August 11, 2025

    AXA IM in talks to take stake in Telefónica Spanish fibre venture

    August 11, 2025
    Recent Posts
    • Greedy ruthlessness has had a great PR campaign in business – but these toy shop owners show a better way | Zoe Williams
    • John Oliver on Ice’s crackdown: ‘Trying to drive up arrests at all costs’ | John Oliver
    • AXA IM in talks to take stake in Telefónica Spanish fibre venture
    • Bright Tangerine Halo Universal Base Kit
    • Another Day, Another Merger: Biglaw Firm Scoops Up Midsize Firm Gutted By Departures
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Disclaimer
    • Get In Touch
    • Privacy Policy
    • Terms and Conditions
    © 2025 ThemeSphere. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.