Moneycontrol PRO
Loans
Loans
HomeNewsTechnologySerious security flaw on dating app Bumble could have exposed location data of users

Serious security flaw on dating app Bumble could have exposed location data of users

The flaw could have allowed threat actors to discover home addresses and track their movements in real-time

August 28, 2021 / 17:44 IST
The flaw was discovered by Robert Heaton, software engineer at Stripe

Robert Heaton, a software engineer for payments and transactions company Stripe discovered a major flaw in the dating app Bumble that could have allowed threat actors to gain access to user location data.

This could have been used to look up addresses and even track user location. Heaton discussed the vulnerability in a blog post and the methods he used to test out a trilateration attack.

He ran a script that spoofed an API request to the app and returned a user's general location. Since Bumble doesn't track user location in real-time, the script assumes the app calculates the distance between two users and then rounds it up.

The script then keeps requesting the user location from the app till the threat actor finds a "flipping point." If the location of the target oscillated between 3 or 4 miles, one could infer that the location was 3.5 miles.

This process is repeated till the attacker finds three of these points after which precise triangulation of the target's location becomes possible.

Heaton also managed to find a way to circumvent the premium access checks which require user's to pay a fee by spoofing signature checks.

The flaw was reported to Bumble and Heaton took home a bug bounty of $2,000. The vulnerability was also patched three days after Heaton reported the flaw.

Heaton used HackerOne to report the flaw to Bumble on 15th June and the fix was deployed on June 18. A full disclosure of the triangulation flaw was agreed upon and released on July 21.

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

Moneycontrol News
first published: Aug 28, 2021 05:44 pm

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347