Tinder security threat could turn off users

One of the world’s most popular dating apps is vulnerable to data theft from hackers, security researchers have revealed.

Researchers at vpnMentor found vulnerabilities in Tinder’s platform through use of their domain - with other online platforms such as Shopify, Yelp, Western Union also identified as being at risk.

“The DOM-XSS vulnerabilities found in Tinder, Shopify, Yelp, Western Union, and Imgur, and the data exposure risks created by them, exemplifies the risks that consumers are exposed to in browser-based applications,” says Rusty Carter, VP of Product Management at application-security company Arxan.

Vulnerable

The vulnerability has been found by white hat hackers but in the wrong hands could be dangerous. Through adding a cross-site scripting flaw, which is available at go.tinder.com, malicious hackers could insert a piece of scripting code to steal user data and hijack accounts. 

The multiple XSS vulnerabilities found by vpnMentor could be used to exploit not only the personal data of uses on these platforms, but also images, ecommerce and money transfers. The security flaw found is part of the branch.io internet tookit, which is widely used across the web and could put up to 685 million people at risk.

The magnitude of this vulnerability should not be underestimated. The Magecart airline breach in September 2018, through just a few lines of vulnerable coding, saw almost 400,000 people’s financial data exposed.  

The security flaw was reported to branch.io who state they were able to patch the security issue before any user data was exposed or exploited, however the danger remains real. Dating app information, like that available in Tinder contains not only financial information but also data points such as sexual orientation and relationship status.

This security flaw has been patched as per current information available, however sheds important light on the continued importance of user data privacy.

Robin Wilding is the creator of the Lead Gen Factory.  She has over 15 years of working experience. She is hardworking and is passionate for technology. 

Latest in Security
Data leak
Hacked Tata Technologies data leaked by ransomware gang
A close-up photo of an iPhone, with the App Store icon prominent in the center of the image.
Thousands of iOS apps found to expose user data and leak Stripe keys
China
Chinese hackers targeting Juniper Networks routers, so patch now
Google Chrome dark mode
Google updates Chrome extension rules to ban affiliate link injection without user action or benefit
Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard
This worrying botnet targets unsecure TP-Link routers - thousands of devices already hacked
Avast cybersecurity
UK cybersecurity sector could be worth £13bn, research shows
Latest in News
UK Prime Minister Sir Kier Starmer
UK PM says AI should soon replace civil servants
Eight Samsung TVs mounted to the wall showing different basketball games
Samsung is offering you 8 new TVs in one bundle for March Madness, in case you want to watch all games at once like a Bond villain’s lair
The Steam Logo on a mobile phone in front of a wall of games.
Today’s Steam Spring Sale features my absolute favorite game of all time - here's when the sale starts and all the key info
Apple iPhone 16 Pro Max REVIEW
The latest iPhone 17 Pro Max leak may have given us another look at its upcoming redesign
Half-Life running on a smartwatch
This Redditor installed a game engine on their smartwatch, and now it runs Doom, Quake, and Half-Life
Samsung Galaxy Z Fold 6
The Samsung Galaxy Z Fold 7 could be in line for a Galaxy S25 Ultra-level camera upgrade