Dating app Raw exposed users’ location data and personal information

Security Flaw in Dating App Raw Exposed User Profiles and Location Data
Photo: TechCrunch

Security Flaw in Dating App Raw Exposed User Profiles and Location Data

A major security vulnerability in the dating app Raw resulted in the exposure of sensitive user information, including exact location data and personal preferences. Launched in 2023 and boasting over 500,000 Android downloads, Raw encourages daily selfie uploads to promote authentic interactions. However, TechCrunch discovered that the app was leaking users’ private data via insecure server endpoints that lacked proper authentication. Anyone with a web browser could access user profiles by altering the 11-digit user ID in a specific API call, a known vulnerability known as an IDOR (Insecure Direct Object Reference). This flaw allowed unauthorized access to names, birthdates, dating and sexual preferences, and precise locations of users. Despite Raw’s claims of using end-to-end encryption, TechCrunch’s testing revealed no such protection in place. The company patched the vulnerability shortly after being alerted but had not previously undergone a third-party security audit. Raw’s co-founder, Marina Anderson, confirmed the fix and stated that a report would be submitted to data protection authorities, although there was no commitment to notifying affected users. The incident raises ethical and security concerns, especially given the company’s plans to launch a wearable device, the Raw Ring, which would track intimate biometric data like heart rate to detect possible infidelity.

Leave a Reply

Your email address will not be published. Required fields are marked *