OkCupid is one of the most popular dating apps that has more than 50 million registered users and used in 110 countries. The app was launched first in 2004 by four friends from Harvard.
In 2019, the app claims that they made 91 million connections at an average with an average of 50,000 dates arranged every week. In the pandemic, they observed a 20% increase in the conversation.
Here to make connections, OkCupid builds personal profiles for all its users by requesting detailed personal information to make a match. The sensitive information is used by hackers to launch targeted attacks.
The vulnerabilities found by researchers with app version Version 40.3.1 which was released on Apr 29, 2020, the most recent version is Version 43.3.2, which was released yesterday.
The app uses deep links functionality which lets attackers include a custom link with the app manifest file to open a web view (browser) window with JavaScript enabled and it returns the user cookies.
Check Point researchers found https://www.OkCupid.com, is vulnerable to an XSS attack. The injection point found under user settings functionality.
In the web, the platform found that the CORS(Cross-Origin Resource Sharing) policy of the API server api.OkCupid.com is not configured properly and any origin can send requests to the server and read its’ responses.
The chain of vulnerabilities could allow attackers too;
Check Point Research reported the vulnerabilities to OkCupid and they managed to fix the vulnerabilities in 48hrs. “Not a single user was impacted by the potential vulnerability on OkCupid,” the company said.
Users are recommended to update with the laters version(43.3.2) to mitigate the risks.
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity, and hacking news updates.
Also Read
Hackers Infect More than 500,000 Routers Worldwide with a Potentially Destructive VPNFilter Malware
New eCh0raix Ransomware Attacking Linux File Storage Servers
INE Security, a leading global provider of cybersecurity training and certifications, today announced a new…
In a groundbreaking discovery on November 20, 2024, cybersecurity researchers Shubham Shah and a colleague…
A security flaw found in Android-based kiosk tablets at luxury hotels has exposed a grave…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued six Industrial Control Systems (ICS) advisories…
A sophisticated cyber campaign dubbed "J-magic" has been discovered targeting enterprise-grade Juniper routers with a…
In January, Netskope Threat Labs uncovered a sophisticated global malware campaign leveraging fake CAPTCHA pages…