Connect with us

Hi, what are you looking for?

Technology

Lovense Faces Backlash Over Prolonged Email Leak Vulnerability

Lovense, the manufacturer of internet-connected sex toys, has come under scrutiny for failing to address a significant security vulnerability that exposed user email addresses for several months. Despite being informed about the issue by security researcher BobDaHacker in March 2023, the company reportedly delayed implementing a fix, leading to ongoing concerns about user privacy.

According to reports from TechCrunch and Bleeping Computer, BobDaHacker discovered that the app’s application programming interface (API) allowed anyone to convert a username into an email address. This vulnerability posed a serious risk, as it could enable an individual to take control of another user’s account. BobDaHacker noted that this flaw was particularly harmful for cam models who often share their usernames publicly but do not wish for their personal email addresses to be revealed.

In a blog post detailing the findings, BobDaHacker highlighted how the vulnerability could be exploited by sending a modified request to Lovense’s servers. This manipulation prompted the system to reveal the associated email address of the target user. The researcher even created a script capable of converting usernames into email addresses in under a second.

The timeline of Lovense’s response has raised eyebrows. BobDaHacker reported the vulnerabilities in partnership with the Internet of Dongs, a group dedicated to enhancing the security of internet-connected sex toys. Lovense initially claimed to have resolved the account takeover issue in April 2023, but BobDaHacker refuted this assertion, stating that the problem remained unaddressed.

In an effort to explain the delays, Lovense mentioned that while a rapid fix was considered, it would require all users to upgrade immediately, disrupting support for legacy versions of the app. The company estimated that a comprehensive solution to the email leak issue would take approximately 14 months to implement.

BobDaHacker pointed out that similar vulnerabilities had been reported to Lovense by security researchers earlier in 2023. However, it appears that these reports were closed without proper resolution, further highlighting the ongoing concerns surrounding the company’s commitment to user security.

In a statement to Bleeping Computer, Lovense asserted that an app update has been submitted to app stores, addressing the latest vulnerabilities. The company stated, “The full update is expected to be pushed to all users within the next week. Once all users have updated to the new version and we disable older versions, this issue will be completely resolved.”

As of now, Lovense has not provided a response to inquiries from The Verge regarding the ongoing situation. The delay in addressing such a critical security vulnerability raises important questions about user safety in the rapidly evolving market of connected devices.

You May Also Like

Lifestyle

Shares of **Amerant Bancorp** (NYSE:AMTB) received an upgrade from Wall Street Zen on March 10, 2024, transitioning from a hold rating to a buy...

Top Stories

UPDATE: Sydney Sweeney’s Baskin-Robbins advertisement is making waves online as backlash intensifies over her recent American Eagle campaign. Just days after critics condemned the...

Sports

The UFC event in Abu Dhabi on July 26, 2025, featured a record-breaking performance from Steven Nguyen, who achieved an unprecedented feat by knocking...

Top Stories

BREAKING: The historic Durango-La Plata Aquatic Center, a cornerstone of community recreation since its opening in August 1958, is facing imminent demolition as part...

Business

An off-Strip casino in Las Vegas has unveiled Nevada’s latest sportsbook, Boomer’s Sports Book, as part of a substantial renovation. The new facility opened...

Top Stories

URGENT UPDATE: Affordable motorcycle helmets under ₹1000 are now available for safety-conscious riders across India. With road safety becoming a pressing issue, these helmets...

Sports

The Las Vegas Aces secured a convincing victory over the Los Angeles Sparks, defeating them 89-74 on March 12, 2024, at Crypto.com Arena. This...

Health

The ongoing impact of poverty on children’s health has prompted urgent calls for action from mental health advocacy groups. With a notable rise in...

Health

Translucent, an innovative start-up specializing in artificial intelligence, has secured $7 million in seed funding to enhance its technology aimed at helping healthcare organizations...

Sports

As the 2025 NFL season approaches, fantasy football enthusiasts are gearing up for their drafts, particularly focusing on tight ends. With players like Brock...

Technology

Polish cyclist Michał Kwiatkowski returned to competitive racing on Saturday at the Clásica San Sebastián, marking his first event in 141 days following a...

Top Stories

California has taken a stand against a federal directive from the Trump administration demanding the exclusion of transgender athletes from girls’ and women’s sports....

Copyright © All rights reserved. This website provides general news and educational content for informational purposes only. While we strive for accuracy, we do not guarantee the completeness or reliability of the information presented. The content should not be considered professional advice of any kind. Readers are encouraged to verify facts and consult appropriate experts when needed. We are not responsible for any loss or inconvenience resulting from the use of information on this site.