Lovense has finally fixed its account takeover problem

0
26

Lovense has finally fixed its account takeover problem

Lovense is well-known for its selection of remote-controlled vibrators. It’s slightly less known for a massive security issue that exposed user emails and allowed accounts to be wholly taken over by a hacker without even needing a password. Fortunately, both issues have been fixed, but it didn’t happen without some drama. 

As the story goes, security researcher BobDaHacker (with some help) accidentally found out that you could uncover a user’s email address pretty easily by muting someone in the app. From there, they were able to figure out that you could do this with any user account, effectively exposing every Lovense user’s email without much effort. 

With the email in hand, it was then possible to generate a valid gtoken without a password, giving a hacker total access to a person’s Lovense account with no password necessary. The researchers told Lovense of the issue in late March and were told that fixes were incoming. 

Mashable Light Speed

In June 2025, Lovense told the researchers that the fix would take 14 months to implement because it did not want to force legacy users to upgrade the app. Partial fixes were implemented over time, only partially fixing the problems. On July 28, the researchers posted an update showing that Lovense was still leaking emails and had exposed over 11 million user accounts. 

"We could have easily harvested emails from any public username list," BobDaHacker said in a blog post. "This is especially bad for cam models who share their usernames publicly but obviously don't want their personal emails exposed."

It was around then that the news started making its way around the news cycle. Other researchers began reaching out to show that the exploit had actually been known as far back as 2022, and Lovense had closed the issue without issuing a fix. After two more days in the news cycle, the sex toy company finally rolled out fixes for both exploits on July 30. 

It’s not Lovense’s first roll in the mud. In 2017, the company was caught with its proverbial pants down after its app was shown to be recording users while they were using the app and toy. Lovense fixed that issue as well, stating that the audio data was never sent to their servers.

Αναζήτηση
Κατηγορίες
Διαβάζω περισσότερα
Παιχνίδια
Rainbow Six Siege X and Borderlands are having a surprise crossover
Rainbow Six Siege X and Borderlands are having a surprise crossover As an Amazon Associate, we...
από Test Blogger6 2025-07-09 17:00:17 0 472
Παιχνίδια
Ayaneo is making a new AMD-powered Nintendo DS handheld with an OLED screen
Ayaneo is making a new AMD-powered Nintendo DS handheld with an OLED screen As an Amazon...
από Test Blogger6 2025-06-10 17:00:18 0 1χλμ.
Παιχνίδια
Best Sims 4 expansion packs 2025
Best Sims 4 expansion packs 2025 As an Amazon Associate, we earn from qualifying purchases...
από Test Blogger6 2025-07-16 10:00:14 0 356
Technology
Dont wait, upgrade your OS to Windows 11 Pro
Windows 11 Pro for $15 TL;DR: Upgrade your PC with Windows 11...
από Test Blogger7 2025-07-28 05:00:20 0 136
Παιχνίδια
ILL is real, and it might be the most brutal horror FPS since the original FEAR
ILL is real, and it might be the most brutal horror FPS since the original FEAR As an Amazon...
από Test Blogger6 2025-06-07 00:00:12 0 1χλμ.