Security researcher BobDaHacker revealed two critical vulnerabilities in Lovense's sex toy app. The flaws expose user email addresses and allow account takeovers using only the email. Despite reporting the issues in March and receiving a $3,000 bug bounty, Lovense requested 14 months to fix them, prompting public disclosure. This impacts millions of Lovense users, raising serious privacy concerns, especially for cam models who publicly share their usernames. Lovense has yet to respond to inquiries.
Prepared by Jonathan Pierce and reviewed by editorial team.
Comments