Grindr, one of the largest dating and social networking apps in the world for gay, bisexual, trans and queer people, fixed a security vulnerability that allowed anyone to hijack and take control of any user's account using only their email address.
Wassime Bouimadaghene, a French security researcher, discovered the vulnerability and reported the problem to Grindr. When he received no response, Bouimadaghene shared details of the vulnerability with security expert Troy Hunt to help.
The vulnerability was fixed shortly after.
Hunt tested and confirmed the vulnerability with the help of a test account created by Scott Helme and shared his findings with ProWellTech.
Bouimadaghene discovered the vulnerability in the way the app handles account password resets.
To reset a password, Grindr sends the user an email with a clickable link containing an account password reset token. Once clicked, the user can change their password and is authorized to re-enter their account.
But Bouimadaghene found that Grindr's password reset page was leaking password reset tokens in the browser. This meant that anyone could trigger a password reset who knew a user's registered email address and collect the password reset token from the browser if they knew where to look.
The clickable link Grindr generates for a password reset is formatted the same way, meaning an attacker could easily create their own clickable link to reset their password - the same link that was sent to the user's inbox. - using the password reset token leaked from the browser.
With that link created, the attacker can reset the account owner's password and gain access to their account and personal data stored within, including account photos, messages, sexual orientation, and HIV status and the date of the last test.
"This is one of the most basic account acquisition techniques I've ever seen," wrote Hunt.
In a statement, Grindr chief operating officer Rick Marini he told ProWellTech: "We are grateful to the researcher who identified a vulnerability. The reported problem has been resolved. Fortunately, we believe we have solved the problem before it was exploited by malicious parties. "
"As part of our commitment to improve the safety and security of our service, we are partnering with a leading security company to simplify and improve the ability of security researchers to report issues such as these. Additionally, we will soon announce a new bug bounty program to provide additional incentives for researchers to help us keep our service secure in the future, "the company said.
Grindr has around 27 million users, of which around 3 million use the app every day. Grindr was sold earlier this year by its former Chinese owner, Beijing Kunlun, to a Los Angeles-based company said to be largely American-led, following allegations that Chinese ownership of the company it posed a threat to national security.
Last year, it was reported that while it was Chinese-owned, Grindr allowed Beijing engineers to access the personal data of millions of US users, including their private messages and HIV status.
You can send suggestions securely via Signal and WhatsApp at +1 646-755-8849 or send an encrypted email to: zack.whittaker@protonmail.com