Tumblr Fixes Critical Security Bug That Exposes User Account Details

Tumblr Fixes a security bug with its desktop version that allows an attacker to steal the user’s personal information.

The bug appears to be in the “Recommended Blogs” section with the desktop version of the Tumblr. The future is available for users only after login and it shows the list of blogs the user follows.

Tumblr said that “it was possible, using debugging software in a certain way, to view certain account information associated with the blog.”

The bug was found by a security researcher who participated in the bug bounty program and the bug was fixed by Tumblr within 12hrs.

“Most importantly, there is no action required of you. We’ve resolved the issue, and have no evidence of this security bug being abused,” Tumblr said.

The bug allows an attacker to access certain user account information such as email address, hashed password, self-reported location, previously used email addresses, last login IP address, and the name of the blog associated with the account.

Tumblr said there is no evidence that this bug was abused, and there is nothing to suggest that unprotected account information was accessed.

Tumblr is a microblogging and social networking website, it allows users to post multimedia contents and a short-form blog.

Facebook admitted a security breach last month that impacts 30 million user accounts, hackers gained access by exploiting a bug with “View As” feature.

Google announced Google+ shut down following the security breach that exposed 500,000 Google+ accounts.

Related Read

Hackers Exploited Facebook Zero-Day Flaw & Stolen 50 Million Accounts Access Tokens

Hackers Selling Facebook Account Logins Details On Dark Web For $3

Gurubaran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

Japan Sounds Alarm Over Hackers Draining Millions from Compromised Trading Accounts

Cybersecurity in Japan has hit a new low as the Financial Services Agency (FSA) reports…

33 minutes ago

FBI Alerts Public to Scammers Posing as IC3 Officials in Fraud Scheme

The Federal Bureau of Investigation (FBI) has issued a warning regarding an emerging scam where…

41 minutes ago

CISA Issues Warning Against Using Censys, VirusTotal in Threat Hunting Ops

 The Cybersecurity and Infrastructure Security Agency (CISA) has alerted its threat hunting teams to immediately…

1 hour ago

PoC Released for Critical Unauthenticated Erlang/OTP RCE Vulnerability

A critical remote code execution (RCE) vulnerability in Erlang/OTP’s SSH implementation (CVE-2025-32433) has now entered…

2 hours ago

Critical Flaw in Windows Update Stack Enables Code Execution and Privilege Escalation

A newly discovered vulnerability in the Windows Update Stack, tracked as CVE-2025-21204, has sent shockwaves…

3 hours ago

WordPress Ad-Fraud Plugins Trigger Massive 1.4 Billion Daily Ad Requests

Cybersecurity researchers have uncovered a sprawling ad-fraud operation exploiting WordPress plugins to trigger over 1.4…

3 hours ago