HomeSecurityVulnerability in Lovense's sex toy app exposes user emails

Vulnerability in Lovense's sex toy app exposes user emails

The connected sex toy platform, Lovense, is vulnerable to a zero-day vulnerability that allows an attacker to gain access to a user's email address simply by knowing the username, exposing them to the risk of doxxing and harassment.

See also: Vulnerability in Post SMTP plugin puts WordPress sites at risk

Lovense vulnerability

Lovense is a maker of interactive sex toys, best known for its app-controlled toys like Lush, Gush , and—perhaps most daringly— Kraken. The company claims to have 20 million customers worldwide.

While Lovense games are widely used for both local and remote entertainment, they are also particularly popular with cam models, who allow viewers to send tips or sign up to gain remote control over their games. However, this connected experience can expose their Lovense username, and due to the vulnerability, potentially reveal their private email address.

Usernames on Lovense are often shared publicly on forums and social media, making them easy targets for attacks. The vulnerability was discovered by security researcher BobDaHacker, in collaboration with researchers Eva and Rebane, who analyzed the application and automated the attack through reverse engineering.

Researchers disclosed two vulnerabilities four months ago, on March 26, 2025. However, only one of them – a critical vulnerability that allowed for complete account compromise– was patched.

See also: SonicWall patches critical SMA 100 vulnerability

The vulnerability arises from the interaction between Lovense's XMPP chat system, which is used for communication between users, and the platform's backend. To exploit the vulnerability, an attacker makes a POST request to the API endpoint /api/wear/genGtoken using their own credentials. The response includes a gtoken (an authentication token) as well as AES-CBC.

Vulnerability in Lovense's sex toy app exposes user emails

The attacker then takes any publicly known Lovense username and encrypts it with the obtained keys. This encrypted content is sent to the API endpoint /app/ajaxCheckEmailOrUserIdRegisted?email={encrypted_username}.

The server responds with data that includes a fake email address, which the researcher converted into a fake Jabber ID (JID) – the form of identity used on Lovense’s XMPP server. By adding this fake JID to the XMPP contact list and sending a presence subscription (something like a friend request), the attacker can refresh their contact list, which now includes both the fake JID and the real one associated with the target account.

The problem lies in the fact that the real JID is constructed based on the user's real email address, in the format username!!!domain.com_w@im.lovense.com, thus allowing the attacker to extract the victim's email address.

See also: Microsoft knew about SharePoint vulnerability but failed to fix it

The researchers confirmed that the entire process can be completed in less than a second per user, using a suitable script. Furthermore, they stated that it is not necessary to accept the friend request to exploit the vulnerability.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS