Security Breach Exposes Private Photos from Niche Dating Apps
Researchers have discovered a significant security flaw in several niche dating apps developed by M.A.D Mobile, exposing nearly 1.5 million private user images online without password protection. The affected apps include BDSM People, Chica, and LGBT services like Pink, Brish, and Translove, which serve an estimated 800,000 to 900,000 users. The images, many of which are explicit, were accessible to anyone with the link and included not only profile pictures but also privately sent photos and those removed by moderators. Ethical hacker Aras Nazarovas from Cybernews first identified the vulnerability by analyzing the apps’ code and was able to access the unencrypted photos without a password. M.A.D Mobile was initially alerted about the issue on January 20 but did not take action until contacted by the BBC. The company has since fixed the issue but has not disclosed how it occurred or why they failed to secure the images earlier. This breach poses significant risks to users, particularly those living in countries hostile to LGBT individuals, where such exposure could lead to persecution or extortion.
