Close Menu
TechurzTechurz

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    I tried smart glasses with xMEMS speakers and active cooling – and they’re full of promise

    October 13, 2025

    Researchers Warn RondoDox Botnet is Weaponizing Over 50 Flaws Across 30+ Vendors

    October 13, 2025

    Gladinet file sharing zero-day brings patched flaw back from the dead

    October 13, 2025
    Facebook X (Twitter) Instagram
    Trending
    • I tried smart glasses with xMEMS speakers and active cooling – and they’re full of promise
    • Researchers Warn RondoDox Botnet is Weaponizing Over 50 Flaws Across 30+ Vendors
    • Gladinet file sharing zero-day brings patched flaw back from the dead
    • Buying an Android smartwatch? I found a model that’s highly functional and affordable
    • WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More
    • Aisuru’s 30 Tbps botnet traffic crashes through major US ISPs
    • See It Here First at TechCrunch Disrupt 2025
    • Final Flash Sale: Save up to $624 on Disrupt 2025 Passes
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechurzTechurz
    • Home
    • AI
    • Apps
    • News
    • Guides
    • Opinion
    • Reviews
    • Security
    • Startups
    TechurzTechurz
    Home»Apps»Lovense was told its sex toy app leaked users’ emails and didn’t fix it
    Apps

    Lovense was told its sex toy app leaked users’ emails and didn’t fix it

    TechurzBy TechurzJuly 30, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Lovense was told its sex toy app leaked users’ emails and didn’t fix it
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Lovense, the maker of internet-connected sex toys, left user emails exposed for months — even after it became aware of the vulnerability. In a blog post spotted by TechCrunch and Bleeping Computer, security researcher BobDaHacker found that they could “turn any username into their email address,” which they could then use to take over someone’s account.

    Though BobDaHacker initially disclosed this vulnerability to Lovense in March, the researcher claims Lovense waited months before fixing it, and still hasn’t fully addressed the issue. Lovense is behind a range of sex toys that users can connect to the internet and remotely control via its app, which came under fire for a “minor bug” in 2017 that recorded users’ sex sessions.

    As outlined in BobDaHacker’s post, the security researcher noticed something strange in the app’s API response when muting someone: it presented their email address. BobDaHacker then figured out that they could take advantage of this vulnerability by sending a modified request to Lovense’s servers, tricking it into returning the target user’s email address.

    BobDaHacker even developed a script that they say can convert someone’s username into an email address in less than a second. “This is especially bad for cam models who share their usernames publicly but obviously don’t want their personal emails exposed,” BobDaHacker writes. To make matters worse, BobDaHacker later discovered that they could take over a user’s account with their email address and an authentication token generated by Lovense.

    BobDaHacker initially reported these vulnerabilities in partnership with the Internet of Dongs, a group that aims to make internet-connected sex toys more secure. However, the security researcher says Lovense didn’t immediately fix the issue. Instead, Lovense claimed that the account takeover bug was fixed in April, even though BobDaHacker said it wasn’t, and that a fix for the email leak issue would take 14 months to roll out.

    “We also evaluated a faster, one-month fix. However, it would require forcing all users to upgrade immediately, which would disrupt support for legacy versions,” Lovense said, according to BobDaHacker. As noted by BobDaHacker, security researchers reported the same account takeover bug to Lovense in 2023, but the company appears to have closed the bug without actually fixing it.

    In a statement to Bleeping Computer, Lovense says it has submitted an app update “addressing the latest vulnerabilities” to app stores. “The full update is expected to be pushed to all users within the next week,” Lovense says. “Once all users have updated to the new version and we disable older versions, this issue will be completely resolved.” Lovense didn’t immediately respond to The Verge’s request for comment.

    app Didnt emails fix leaked Lovense Sex told toy users
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleThese AI Tools Are Helping Me Plan for Retirement. Here’s How It’s Going So Far
    Next Article Warning: Protect your phone from choicejacking before it’s too late – here’s how
    Techurz
    • Website

    Related Posts

    Opinion

    Dating app Cerca will show how Gen Z really dates at TechCrunch Disrupt 2025

    October 12, 2025
    Security

    Spotty Wi-Fi at home? 5 products I recommend to fix it once and for all

    October 11, 2025
    Security

    Free AI-powered Dia browser now available to all Mac users – Windows users can join a waitlist

    October 9, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    The Reason Murderbot’s Tone Feels Off

    May 14, 20259 Views

    Start Saving Now: An iPhone 17 Pro Price Hike Is Likely, Says New Report

    August 17, 20258 Views

    CNET’s Daily Tariff Price Tracker: I’m Keeping Tabs on Changes as Trump’s Trade Policies Shift

    May 27, 20258 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    The Reason Murderbot’s Tone Feels Off

    May 14, 20259 Views

    Start Saving Now: An iPhone 17 Pro Price Hike Is Likely, Says New Report

    August 17, 20258 Views

    CNET’s Daily Tariff Price Tracker: I’m Keeping Tabs on Changes as Trump’s Trade Policies Shift

    May 27, 20258 Views
    Our Picks

    I tried smart glasses with xMEMS speakers and active cooling – and they’re full of promise

    October 13, 2025

    Researchers Warn RondoDox Botnet is Weaponizing Over 50 Flaws Across 30+ Vendors

    October 13, 2025

    Gladinet file sharing zero-day brings patched flaw back from the dead

    October 13, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2025 techurz. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.