Tinder vulnerability allows hackers to take over accounts with just one phone number

22 Feb 2018

1

After it was reported last month that online dating app Tinder had a security flaw, which allows strangers to see users' photos and matches, security firm, Appsecure has now uncovered a new flaw which is potentially more damaging.

Infiltrators who exploit the vulnerability will be able to get access to users' account with the help of their login phone number. The issue has, however, been fixed after Tinder was alerted by Appsecure.

Appsecure says, the hackers could have taken advantage of two vulnerabilities to attack accounts, with one being Tinder's own API and the other in Facebook's Account Kit system which Tinder uses to manage the logins.

In a statement sent to The Verge, a Tinder spokesperson said, "Security is a top priority at Tinder. However, we do not discuss any specific security measures or strategies, so as not to tip off malicious hackers."

The vulnerability exposed the access tokens of the users. If a hacker is able to obtain a user's valid access token then he/she can easily take over a user account.

"We quickly addressed this issue and we're grateful to the researcher who brought it to our attention," The Verge quoted a Facebook representative as saying.

Hackers can gain control of Tinder accounts due to a vulnerability in Account Kit by Facebook and the dating app's own implementation of the login process which uses this. Tinder users are asked by the company to sync their Facebook account to access the dating app.

According to the security firm, in Tinder's case the option for mobile number-based login is provided by Facebook's Account Kit, which had a vulnerability.

Latest articles

Carmakers explore energy storage, but claims of major pivot and write-downs are overstated

Carmakers explore energy storage, but claims of major pivot and write-downs are overstated

Government advances Dholera semiconductor hub, but timelines and scale claims need caution

Government advances Dholera semiconductor hub, but timelines and scale claims need caution

South Korea’s AI chip push grows, but 2nm robotics claims remain premature

South Korea’s AI chip push grows, but 2nm robotics claims remain premature

India–Japan chip collaboration grows, but details around Axiro–EdgeCortix deal remain limited

India–Japan chip collaboration grows, but details around Axiro–EdgeCortix deal remain limited

Post-splashdown: What Artemis II taught us about the ‘deep space wall’

Post-splashdown: What Artemis II taught us about the ‘deep space wall’

Carmakers explore energy storage, but claims around Ford and GM pivot remain overstated

Carmakers explore energy storage, but claims around Ford and GM pivot remain overstated

Tesla’s robotics push continues, but Shanghai “Optimus mass production” claims remain unconfirmed

Tesla’s robotics push continues, but Shanghai “Optimus mass production” claims remain unconfirmed

VinFast eyes India growth, but details around VF MPV 7 launch remain unverified

VinFast eyes India growth, but details around VF MPV 7 launch remain unverified

Breaking the engine barrier: HAL and GE move forward on F414 co-production deal

Breaking the engine barrier: HAL and GE move forward on F414 co-production deal