A Vulnerability in Bumble Platform Allows Location Leaks
- Friday, September 17 2021 @ 09:24 am
- Contributed by: kellyseal
- Views: 701
Dating app Bumble’s platform was found to have a security vulnerability capable of leaking the exact locations of its users, putting them at risk of potential attackers.
The researcher who discovered the security flaw created two fake profiles, one for the “attacker” and one for the “victim,” to check vulnerabilities in the app’s API. He was able to bypass signature checks for API requests, which meant he got around Bumble’s paywall to execute the attack.
His test revealed the exact location and the distance of the fake victim from the fake attacker through a process of trilateration, according to security trade magazine The Daily Swig. In other words, he figured out how the app calculated and matched approximate user locations by rounding down the exact distance they are from each other.




