Newsletter →
HackerDose
HackerDose
  • Latest Stories
  • Security & Tech
    • Cybersecurity
    • Technology
    • Vulnerabilities
    • Dark Web
  • Crypto & Blockchain
    • Cryptocurrency
    • Blockchain
    • Finance
    • Price Predictions
    • Guides
    • Regulation
Reading: Feeld Dating App Breach Left Your Nudes Open to Hackers
Newsletter
Newsletter →
HackerDose
HackerDose
  • Latest Stories
  • Security & Tech
    • Cybersecurity
    • Technology
    • Vulnerabilities
    • Dark Web
  • Crypto & Blockchain
    • Cryptocurrency
    • Blockchain
    • Finance
    • Price Predictions
    • Guides
    • Regulation
Reading: Feeld Dating App Breach Left Your Nudes Open to Hackers
Newsletter
Search
  • Latest Stories
  • Security & Tech
    • Security
    • Vulnerabilities
    • Dark Web
    • Technology
    • Privacy
  • Crypto & Blockchain
    • Cryptocurrency
    • Blockchain
    • Finance
    • Price Predictions
    • Guides
    • Regulation
© MRS Media Company. Hackerdose LLC. All Rights Reserved.

Privacy » Feeld Dating App Breach Left Your Nudes Open to Hackers

PrivacyNewsVulnerabilities

Feeld Dating App Breach Left Your Nudes Open to Hackers

Feeling exposed? Feeld fixed it, but your data was wide open for almost half a year.

Marco Rizal
Last updated: September 12, 2024 6:20 am
By Marco Rizal - Editor, Journalist 5 Min Read
Share
Feeld Dating App Breach Left Your Nudes Open to Hackers
SHARE

Fortbridge security experts revealed many critical vulnerabilities in the Feeld dating app, exposing users' private information such as personal data, chats, and even intimate images and videos.

These problems primarily relate to “broken access control,” one of the top security threats highlighted by the Open Web Application Security Project (OWASP).

The found vulnerabilities enable attackers to see and change data without adequate authentication, posing a serious privacy risk to users.

One of the most alarming vulnerabilities is that attackers can view private user photos, videos, and chats without logging into the app or having the proper permissions.

image 51
Reading other people's messages via streamUserID value. (Credit: Fortbridge)

Feeld's premium features, designed to protect sensitive user information, are simply circumvented with simple hacking tools.

This means that basic users, who generally see just limited profile information, can use these issues to view other users' whole profiles, images, and communications.

Fortbridge’s research found that attackers could perform several alarming actions, including:

  • Attackers can read private messages between users and gain access to full profiles without permission.
  • Photos and videos exchanged in private chats, including time-limited content, can be viewed without authentication. Even if a photo or video is listed as expired, attackers can still access it using certain URLs.
  • Attackers have the ability to modify or delete other people's messages, which opens up the possibility of discussion manipulation and misinformation.
  • In some situations, attackers can change someone else's profile information, such as age, gender, and interests.

These flaws pose major dangers to user privacy, particularly given the sensitive nature of the information transmitted on dating sites such as Feeld.

Personal information like as photographs, sexual preferences, and messages may be disclosed to unauthorized third parties, putting users at risk of privacy infringement.

How Attackers Exploit the System

Fortbridge disclosed vulnerabilities that allow attackers to intercept and extract sensitive data from Feeld's API (application programming interface) using tools such as Burp Suite.

Hackers can bypass security safeguards designed to secure user information by changing specific parameters in Feeld's API, allowing anyone to gain unauthorized access to private conversations, photographs, or videos.

One of the flaws, for example, enables attackers to retrieve the URLs of shared multimedia assets.

image 50
Video being shown unauthenticated and is replay-able. (Credit: Fortbridge)

These cloud-stored files can be read and downloaded without requiring any login. Even after a photo or video is meant to have expired, it can still be accessed using these URLs.

Fortbridge reported these concerns to Feeld, although it is unclear whether all vulnerabilities have been addressed.

The business has recommended users to exercise caution while sharing sensitive media and personal information on the site until these vulnerabilities have been fully resolved.

Delayed Disclosure

The disclosure of these vulnerabilities sparked concerns among users, particularly concerning how long these problems went unpatched.

Many are wondering if Feeld's answer was timely enough. Some users were frustrated, questioning why Fortbridge did not quickly report the original vulnerability upon detection, rather than waiting to investigate the entire scope of the security vulnerabilities.

As one user asked, “At what point is it irresponsible not to disclose an initial vulnerability?”

image 52
Feeld vulnerability disclosure timeline via Fortbridge

Given that Feeld has been around for a decade, the timeline of the investigation is causing concern, as the vulnerabilities could have been open for years, leaving user data exposed.

While Feeld eventually resolved the issues, many users were dissatisfied with the delayed process.

Some claim that Feeld should have prioritized correcting these major vulnerabilities before feature updates or other bug fixes, considering the risk to user privacy.

Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Subscribe to our newsletter

Receive the latest news and stories straight to your inbox.

Latest stories

Bitcoin Holds at $85K as Global Trade Tensions and Fed Speculation Unfold

April 15, 2025

Michael Saylor Doubles Down on Bitcoin (BTC) with $285M Investment Amid Global Uncertainty

April 14, 2025

Mantra Faces Crisis After OM Token Crashes 90% in a Day

April 14, 2025

Solana (SOL) on the Verge of a Breakout: Could $300 Be the Next Target?

April 14, 2025

You might also like

Threat Actor Exposes Multiple Vulnerabilities in FBI Online Portal

Threat Actor Exposes Multiple Vulnerabilities in FBI Online Portal

Major Security Flaws Found in Widely Used Discourse Forum

Major Security Flaws Found in Widely-Used Discourse Forum

Largest FIN7 Malware Campaign Targets Global Companies Across 4000 Domains

Largest FIN7 Malware Campaign Targets Global Companies Across 4000 Domains

Google Patches Serious Android Security Flaws in September Update

Google Patches Serious Android Security Flaws in September Update

Newsletter

Our website stores cookies on your computer. They allow us to remember you and help personalize your experience with our site

Quick Links

  • Contact Us
  • Search
  • Malware
  • Downloads

Company

  • About Us
  • Terms and Conditions
  • Cookies Policy
  • Privacy Policy
Advertise with us

Socials

Follow Us

© 2025 | HackerDose Media Company – All Rights Reserved

Welcome Back!

Sign in to your account

Lost your password?