Security Flaws Discovered in OKCupid Dating Service
Researchers identified a variety of vulnerabilities in apps and websites for the popular online dating platform.
Researchers at Check Point recently found that the mobile app and website for dating service OKCupid contained multiple vulnerabilities that could allow a malicious user to perform actions ranging from stealing users' personal data to performing in-app actions on behalf of those users.
The vulnerabilities included off-app access to deep links within the app, cross-site scripting on the main OKCupid website, and malicious JavaScript injection in deep links.
According to researchers Alon Boxiner and Eran Vaknin, OKCupid was informed of the vulnerabilities and patched them prior to their disclosure of the flaws. The researchers say their work shows the importance of secure development, especially in the current era of social distancing. "The dire need for privacy and data security becomes far more crucial when so much private and intimate information being stored, managed and analyzed in an app," they wrote. "The app and platform was created to bring people together, but of course where people go, criminals will follow, looking for easy pickings."
For more, read here.
Register now for this year's fully virtual Black Hat USA, scheduled to take place August 1–6, and get more information about the event on the Black Hat website. Click for details on conference information and to register.
About the Author
You May Also Like
How to Evaluate Hybrid-Cloud Network Policies and Enhance Security
September 18, 2024DORA and PCI DSS 4.0: Scale Your Mainframe Security Strategy Among Evolving Regulations
September 26, 2024Harnessing the Power of Automation to Boost Enterprise Cybersecurity
October 3, 202410 Emerging Vulnerabilities Every Enterprise Should Know
October 30, 2024
State of AI in Cybersecurity: Beyond the Hype
October 30, 2024[Virtual Event] The Essential Guide to Cloud Management
October 17, 2024Black Hat Europe - December 9-12 - Learn More
December 10, 2024SecTor - Canada's IT Security Conference Oct 22-24 - Learn More
October 22, 2024