HomeSecurityOkCupid: The dating website exposes personal data!

OkCupid: Dating website exposes personal data!

According to several expert publications, the dating website, OkCupid, has a vulnerability within the application that could allow hackers to access user data.

The flaw was discovered by researchers at Checkmarx in Israel, whose findings were published in a recent Threatpost article.

“The vulnerability (…) occurs because OkCupid’s ‘Webview’ recognizes any URL that contains the characters, ‘/l/’ and passes them as a MagicLink. This means that the link does not redirect outside the app but to the hybrid Webview of OkCupid’s Android app.”

Users could easily mistake a fake login page for the legitimate one if it appeared within the app.

OkCupid

The credentials obtained are sent to hackers who then have the ability to impersonate, bribe, or threaten users in any way.

The vulnerability can also expose location information, which is considered critical especially for physical security reasons.

OkCupid, for its part, had expressed concerns about a possible hacking attack since February 14.

At the time, a company spokesperson said: “There was no website error on OkCupid. (…) All websites face account hacking attempts all the time. OkCupid is no exception.”

There is no update regarding the vulnerability fix.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS