Last year, security researcher Jamal Eddine discovered a bug in Foursquarethat could have been exploited by cybercriminals to obtain the primary email addresses of any user of the social network.
The security flaw was immediately addressed by the social network, but the expert only published his findings a few days ago.
The bug was found in friend requests sent between users. The request URL contains a parameter called “uid,” which is linked to the sender’s email address.
By changing the value of the variable, the primary email address of any Foursquare user could be obtained.
The researcher notified the company of the security flaw, which was patched within 24 hours. Foursquare does not have a bug bounty program to reward the researcher, but it did include his name in its Hall of Fame. Additional information about the vulnerability is available on Eddine's blog.

