Technology7/29/2025β€’Engadget

A Lovense security flaw may be letting people take over accounts without a password

A Lovense security flaw may be letting people take over accounts without a password

Lovense, a sex toy company, is facing a security flaw that allows account takeovers without a password and discloses users' email addresses, according to a security researcher. The researcher, BobDaHacker, reported the issues to Lovense in 2023, but the company has not fully addressed them. The account takeover bug allows anyone to generate authentication tokens and access accounts, including admin accounts, without a password. The email disclosure flaw allows the researcher to obtain the email addresses associated with any public username in less than a second. Lovense has acknowledged the issues, stating that fixing the email disclosure flaw could take up to 14 months. This is not the first time Lovense has faced privacy concerns, as a previous incident in 2017 revealed the app was recording audio without user consent.

Note: This is an AI-generated summary of the original article. For the full story, please visit the source link below.

Source: EngadgetAI-generated summary
Content is AI-generated for summary purposes only
Share:

Related Articles

Nvidia Is Making a New Chip for China Amid Debate on AI Exports
πŸ’» Technology3h agoβ€’1 min read

Nvidia Is Making a New Chip for China Amid Debate on AI Exports

Source: NYT
Content is AI-generated for summary purposes only
Premier League Soccer: Stream Man City vs. Tottenham Live From Anywhere
πŸ’» Technology4h agoβ€’1 min read

Premier League Soccer: Stream Man City vs. Tottenham Live From Anywhere

Source: CNET
Content is AI-generated for summary purposes only
US Government Makes $8.9B Investment to Take 10% Stake in Intel
πŸ’» Technology5h agoβ€’1 min read

US Government Makes $8.9B Investment to Take 10% Stake in Intel

Source: CNET
Content is AI-generated for summary purposes only
Ex-Employee Sentenced to 4 Years for Sabotaging Company’s Computer Network
πŸ’» Technology5h agoβ€’1 min read

Ex-Employee Sentenced to 4 Years for Sabotaging Company’s Computer Network

Source: NYT
Content is AI-generated for summary purposes only
With Apple's Siri AI Overhaul Delayed, Google Might Help It Catch Up
πŸ’» Technology6h agoβ€’1 min read

With Apple's Siri AI Overhaul Delayed, Google Might Help It Catch Up

Source: CNET
Content is AI-generated for summary purposes only
Intel Agrees to Sell U.S. a 10% Stake in Its Business
πŸ’» Technology6h agoβ€’1 min read

Intel Agrees to Sell U.S. a 10% Stake in Its Business

Source: NYT
Content is AI-generated for summary purposes only