HomeSecurityOver 60% of popular dating apps for Android phones vulnerable

More than 60% of popular dating apps for Android phones vulnerable

Users of online dating services for Android are at risk of losing sensitive personal information as cybercriminals exploit vulnerabilities in mobile apps.

Dating Apps Vulnerabilities
A study of 41 such applications found that in 63% of cases the product shipped with a security gap that could be exploited in some way by a malicious user.

The threat extends to the business environment, beyond the user's personal space, as many individuals often use dating apps on mobile devices that have access to confidential corporate information.

The research, conducted by IBM, determines that security vulnerabilities in popular Android dating apps could be exploited to track a user's movements, gain access to the device's microphone or camera, or compromise a user's dating profile.

“IBM found that 73% of the 41 popular dating apps analyzed have access to current and historical GPS location information,” the company’s report released Wednesday said.

This information becomes useful if cybercriminals are looking for information about a target's tracks over a certain period of time, as they are led to learning about the user's work or home address.

Having access to the video and audio components is also useful for targeted attacks, as they can be used to spy on the victim in order to gather more details. IBM says this feat can be achieved even if the user is not logged into the dating app.

Another risk stemming from app security vulnerabilities is that which leads to a user profile being compromised. This allows third parties to impersonate the victim and contact others in an attempt to trick them into revealing personal data, financial information, or even convincing them to send money to the scammers.

Security researchers from IBM discovered that 26 of the applications analyzed had medium or high severity security vulnerabilities that allow cross-site scripting ( XSS ) or phishing attacks via man-in-the-middle (MITM) techniques

Debug Flag-enabled exploits are also on the list. If the flag is enabled, an app that has debug enabled could "attach" itself to another app and gain access to data written to or read from its memory. This would be a powerful attack because attackers could falsify the information and modify it to suit their purposes.

Recommendations for users to stay safe from a breach include posting as little personal information as possible on their profile, regularly checking device security settings for suspicious modifications, using unique passwords, and installing the latest software updates.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS