The connected sex toy platform, Lovense, is vulnerable to a zero-day vulnerability that allows an attacker to gain access to a user's email address simply by knowing the username, exposing them to the risk of doxxing and harassment.
See also: Vulnerability in Post SMTP plugin puts WordPress sites at risk

Lovense is a maker of interactive sex toys, best known for its app-controlled toys like Lush, Gush , and—perhaps most daringly— Kraken. The company claims to have 20 million customers worldwide.
While Lovense games are widely used for both local and remote entertainment, they are also particularly popular with cam models, who allow viewers to send tips or sign up to gain remote control over their games. However, this connected experience can expose their Lovense username, and due to the vulnerability, potentially reveal their private email address.
Usernames on Lovense are often shared publicly on forums and social media, making them easy targets for attacks. The vulnerability was discovered by security researcher BobDaHacker, in collaboration with researchers Eva and Rebane, who analyzed the application and automated the attack through reverse engineering.
Researchers disclosed two vulnerabilities four months ago, on March 26, 2025. However, only one of them – a critical vulnerability that allowed for complete account compromise– was patched.
See also: SonicWall patches critical SMA 100 vulnerability
The vulnerability arises from the interaction between Lovense's XMPP chat system, which is used for communication between users, and the platform's backend. To exploit the vulnerability, an attacker makes a POST request to the API endpoint /api/wear/genGtoken using their own credentials. The response includes a gtoken (an authentication token) as well as AES-CBC.

The attacker then takes any publicly known Lovense username and encrypts it with the obtained keys. This encrypted content is sent to the API endpoint /app/ajaxCheckEmailOrUserIdRegisted?email={encrypted_username}.
The server responds with data that includes a fake email address, which the researcher converted into a fake Jabber ID (JID) – the form of identity used on Lovense’s XMPP server. By adding this fake JID to the XMPP contact list and sending a presence subscription (something like a friend request), the attacker can refresh their contact list, which now includes both the fake JID and the real one associated with the target account.
The problem lies in the fact that the real JID is constructed based on the user's real email address, in the format username!!!domain.com_w@im.lovense.com, thus allowing the attacker to extract the victim's email address.
See also: Microsoft knew about SharePoint vulnerability but failed to fix it
The researchers confirmed that the entire process can be completed in less than a second per user, using a suitable script. Furthermore, they stated that it is not necessary to accept the friend request to exploit the vulnerability.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
