Security Flaws Discovered in OKCupid Dating ServiceSecurity Flaws Discovered in OKCupid Dating Service
Researchers identified a variety of vulnerabilities in apps and websites for the popular online dating platform.
July 30, 2020

Researchers at Check Point recently found that the mobile app and website for dating service OKCupid contained multiple vulnerabilities that could allow a malicious user to perform actions ranging from stealing users' personal data to performing in-app actions on behalf of those users.
The vulnerabilities included off-app access to deep links within the app, cross-site scripting on the main OKCupid website, and malicious JavaScript injection in deep links.
According to researchers Alon Boxiner and Eran Vaknin, OKCupid was informed of the vulnerabilities and patched them prior to their disclosure of the flaws. The researchers say their work shows the importance of secure development, especially in the current era of social distancing. "The dire need for privacy and data security becomes far more crucial when so much private and intimate information being stored, managed and analyzed in an app," they wrote. "The app and platform was created to bring people together, but of course where people go, criminals will follow, looking for easy pickings."
For more, read here.
Register now for this year's fully virtual Black Hat USA, scheduled to take place August 1–6, and get more information about the event on the Black Hat website. Click for details on conference information and to register.
About the Author(s)
You May Also Like
Hacking Your Digital Identity: How Cybercriminals Can and Will Get Around Your Authentication Methods
Oct 26, 2023Modern Supply Chain Security: Integrated, Interconnected, and Context-Driven
Nov 06, 2023How to Combat the Latest Cloud Security Threats
Nov 06, 2023Reducing Cyber Risk in Enterprise Email Systems: It's Not Just Spam and Phishing
Nov 01, 2023SecOps & DevSecOps in the Cloud
Nov 06, 2023