Technophile NewsTechnophile News
  • Home
  • News
  • PC
  • Phones
  • Android
  • Gadgets
  • Games
  • Guides
  • Accessories
  • Reviews
  • Spotlight
  • More
    • Artificial Intelligence
    • Web Stories
    • Press Release
What's On

Samsung Tri-Fold Phone to Launch in H2 2025; Galaxy S25 FE Teased to Debut Earlier

31 July 2025

The Inside Story of Eric Trump’s American Bitcoin

31 July 2025

Why AI researchers are getting paid like NBA All-Stars

31 July 2025

Amazon Great Freedom Festival Sale 2025: Best Deals on Laptops Under Rs. 50,000

31 July 2025

The Best Video Doorbell Cameras

31 July 2025
Facebook X (Twitter) Instagram
  • Privacy
  • Terms
  • Advertise
  • Contact Us
Thursday, July 31
Facebook X (Twitter) Instagram YouTube
Technophile NewsTechnophile News
Demo
  • Home
  • News
  • PC
  • Phones
  • Android
  • Gadgets
  • Games
  • Guides
  • Accessories
  • Reviews
  • Spotlight
  • More
    • Artificial Intelligence
    • Web Stories
    • Press Release
Technophile NewsTechnophile News
Home » Lovense was told its sex toy app leaked users’ emails and didn’t fix it
News

Lovense was told its sex toy app leaked users’ emails and didn’t fix it

By News Room29 July 20253 Mins Read
Facebook Twitter Pinterest LinkedIn Telegram Tumblr Reddit WhatsApp Email
Share
Facebook Twitter LinkedIn Pinterest Email

Lovense, the maker of internet-connected sex toys, left user emails exposed for months — even after it became aware of the vulnerability. In a blog post spotted by TechCrunch and Bleeping Computer, security researcher BobDaHacker found that they could “turn any username into their email address,” which they could then use to take over someone’s account.

Though BobDaHacker initially disclosed this vulnerability to Lovense in March, the researcher claims Lovense waited months before fixing it, and still hasn’t fully addressed the issue. Lovense is behind a range of sex toys that users can connect to the internet and remotely control via its app, which came under fire for a “minor bug” in 2017 that recorded users’ sex sessions.

As outlined in BobDaHacker’s post, the security researcher noticed something strange in the app’s API response when muting someone: it presented their email address. BobDaHacker then figured out that they could take advantage of this vulnerability by sending a modified request to Lovense’s servers, tricking it into returning the target user’s email address.

BobDaHacker even developed a script that they say can convert someone’s username into an email address in less than a second. “This is especially bad for cam models who share their usernames publicly but obviously don’t want their personal emails exposed,” BobDaHacker writes. To make matters worse, BobDaHacker later discovered that they could take over a user’s account with their email address and an authentication token generated by Lovense.

BobDaHacker initially reported these vulnerabilities in partnership with the Internet of Dongs, a group that aims to make internet-connected sex toys more secure. However, the security researcher says Lovense didn’t immediately fix the issue. Instead, Lovense claimed that the account takeover bug was fixed in April, even though BobDaHacker said it wasn’t, and that a fix for the email leak issue would take 14 months to roll out.

“We also evaluated a faster, one-month fix. However, it would require forcing all users to upgrade immediately, which would disrupt support for legacy versions,” Lovense said, according to BobDaHacker. As noted by BobDaHacker, security researchers reported the same account takeover bug to Lovense in 2023, but the company appears to have closed the bug without actually fixing it.

In a statement to Bleeping Computer, Lovense says it has submitted an app update “addressing the latest vulnerabilities” to app stores. “The full update is expected to be pushed to all users within the next week,” Lovense says. “Once all users have updated to the new version and we disable older versions, this issue will be completely resolved.” Lovense didn’t immediately respond to The Verge’s request for comment.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related News

The Inside Story of Eric Trump’s American Bitcoin

31 July 2025

Why AI researchers are getting paid like NBA All-Stars

31 July 2025

The Best Video Doorbell Cameras

31 July 2025

Nvidia will support GeForce drivers on Windows 10 until October 2026

31 July 2025

The Best Travel Strollers for All Your Family Adventures

31 July 2025

DJI’s first 360-degree camera captures 8K footage for over 100 minutes

31 July 2025
Top Articles

iQOO Neo 10 Pro+ Confirmed to Debut This Month, Pre-Reservations Begin

8 May 2025159 Views

iQOO Neo 10 Pro+ Battery, Charging Specifications Revealed; Will Be Equipped With 6,800mAh Battery

19 May 2025127 Views

iQOO Neo 10 Pro+ With Snapdragon 8 Elite, 6,800mAh Battery Launched: Price, Specifications

20 May 202584 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Don't Miss

Nvidia will support GeForce drivers on Windows 10 until October 2026

31 July 2025

Nvidia is releasing a new GeForce Game Ready Driver today that expands support for Windows…

Amazon Great Freedom Festival Sale 2025: Best Deals on Smartwatches From OnePlus, Samsung, Noise, Amazfit, and More

31 July 2025

Amazon Great Freedom Festival Sale 2025: Best Deals on iPad Air, MacBook, AirPods, Other Apple Products

31 July 2025

iPhone 17 Lineup Could See Price Hikes Across the Board, Except for Standard Model

31 July 2025
Technophile News
Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact Us
© 2025 Technophile News. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.