Wednesday, April 2, 2025
HomeCVE/vulnerabilityOkCupid Vulnerabilities Let Hackers to Steal the Personal and Sensitive Data of...

OkCupid Vulnerabilities Let Hackers to Steal the Personal and Sensitive Data of Users

Published on

SIEM as a Service

Follow Us on Google News

OkCupid is one of the most popular dating apps that has more than 50 million registered users and used in 110 countries. The app was launched first in 2004 by four friends from Harvard.

In 2019, the app claims that they made 91 million connections at an average with an average of 50,000 dates arranged every week. In the pandemic, they observed a 20% increase in the conversation.

Here to make connections, OkCupid builds personal profiles for all its users by requesting detailed personal information to make a match. The sensitive information is used by hackers to launch targeted attacks.

Multiple Flaws Discovered

The vulnerabilities found by researchers with app version Version 40.3.1 which was released on Apr 29, 2020, the most recent version is Version 43.3.2, which was released yesterday.

The app uses deep links functionality which lets attackers include a custom link with the app manifest file to open a web view (browser) window with JavaScript enabled and it returns the user cookies.

Check Point researchers found https://www.OkCupid.com, is vulnerable to an XSS attack. The injection point found under user settings functionality.

In the web, the platform found that the CORS(Cross-Origin Resource Sharing) policy of the API server api.OkCupid.com is not configured properly and any origin can send requests to the server and read its’ responses.

The chain of vulnerabilities could allow attackers too;

  • Expose users’ sensitive data stored on the app.
  • Perform actions on behalf of the victim.
  • Steals users’ profile and private data, preferences, and characteristics.
  • Steals users’ authentication token, users’ IDs, and other sensitive information such as email addresses.
  • Send the data gathered to the attacker’s server.

Check Point Research reported the vulnerabilities to OkCupid and they managed to fix the vulnerabilities in 48hrs. “Not a single user was impacted by the potential vulnerability on OkCupid,” the company said.

Users are recommended to update with the laters version(43.3.2) to mitigate the risks.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity, and hacking news updates.

Also Read

Hackers Infect More than 500,000 Routers Worldwide with a Potentially Destructive VPNFilter Malware

New eCh0raix Ransomware Attacking Linux File Storage Servers

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Python Introduces New Standard Lock File Format for Enhanced Security

The Python Software Foundation (PSF) has officially announced the adoption of a new standardized...

Hackers Exploit Microsoft Teams Messages to Deliver Malware

Cybersecurity experts have uncovered a new malware campaign targeting Microsoft Teams users to infiltrate...

Hackers Exploiting Vulnerabilities in SonicWall, Zoho, F5 & Ivanti Systems

A surge in cyber activity targeting critical edge technologies and management tools, including SonicWall,...

CISA Alerts on Active Exploitation of Apache Tomcat Vulnerability

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a high-priority alert regarding the...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Hackers Exploiting Vulnerabilities in SonicWall, Zoho, F5 & Ivanti Systems

A surge in cyber activity targeting critical edge technologies and management tools, including SonicWall,...

CISA Alerts on Active Exploitation of Apache Tomcat Vulnerability

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a high-priority alert regarding the...

Sliver Framework Customized Enhances Evasion and Bypasses EDR Detection

The Sliver Command & Control (C2) framework, an open-source tool written in Go, has...