Tinder App Lacks Encryption, User's Privacy at Risk: Checkmarx

Advertisement
By Sumit Chakraborty | Updated: 24 January 2018 11:21 IST
Highlights
  • Researchers have disclosed two major flaws in Tinder app
  • Attacker can spy on a user's every move in the app
  • Hacker and user will have to be on the same Wi-Fi network
Tinder App Lacks Encryption, User's Privacy at Risk: Checkmarx

Tinder mobile app lacks security protections, leaving users vulnerable to eavesdropping, a report by security researchers claims. Researchers say the dating app is not using encryption to prevent hackers from snooping on users sharing the same network. Lack of basic HTTPS encryption essentially means that anyone can extract Tinder pictures and other data such as user swipes.

Tel Aviv-based security research firm Checkmarx found the vulnerability on Tinder's Android as well as iOS apps. In order to demonstrate an attack, the firm has created an app called TinderDrift. In a video on YouTube, we can see how such an app could be used to follow Tinder users' actions on Tinder if the person is sharing the same Wi-Fi.

The researchers have disclosed two flaws - CVE-2018-6017 and CVE-2018-6018 - in the app. The report says, "Our research found two vulnerabilities that, once combined, enable a malicious attacker to spy on a Tinder user's every move in the app." This means hackers can see a user's profile, profiles which the user views, as well as actions like swiping left or right, and more. The attacker can follow the user's Tinder matches and seriously compromise the user's privacy, the researchers noted.

Notably, in order to carry out an attack, hackers will have to be on the same Wi-Fi network as the user, the report claims. Since Tinder is an app usually used in public spaces, people are likely used to be accessing public Wi-Fi, leaving themselves potentially exposed. Additionally, other scenarios include VPN connection, DNS poisoning attacks, or malicious Internet service providers.

Advertisement

The report also claims that hackers can use user's private information to potentially swap the photos a user sees for inappropriate content or rogue advertising. It has recommended Tinder users to avoid public Wi-Fi networks wherever possible until developers take steps to make sure all app traffic is secured.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Android 16 Update Is Coming Soon - Here's What to Expect
  2. iOS 26, iPadOS 26 Are Compatible With These iPhone and iPad Models
  3. Motorola Edge 60 With 5,500mAh Battery Launched in India: Price, Offers
  4. Nothing Announces 'Now or Nothing' Sale in India: Check All Offers
  5. UK Appoints First Crypto Specialist to Tackle Web3 Fraud in Insolvency Cases
  6. Nothing Phone 3 Leaked Render Suggests Design, Triple Rear Camera Unit
  7. Realme Announces Limited-Time Discounts on Realme GT 7 Series in India
  8. Vivo Y400 Pro Design, Key Specifications Tipped; May Run on This Chipset
  1. Nothing Announces 'Now or Nothing’ Sale in India for Nothing and CMF-Branded Products
  2. What is Liquid Glass Interface, Apple’s New Universal Design Language for iPhone, iPad, Mac, and Other Devices
  3. Activision Says It's Working With Nintendo to Bring Call of Duty to Switch After Black Ops 7 Reveal
  4. Asus TUF Gaming F16, TUF Gaming A16, ROG Strix G16 and ROG Zephyrus G14 2025 Variants Launched in India
  5. UK Bolsters Web3 Investigations, Appoints First Crypto Intelligence Specialist to Insolvency Service
  6. Latest Windows 11 Insider Preview Lets You Try a New Start Menu With Scrollable Interface, More Features
  7. Vodafone Idea (Vi) Announces Rollout of 5G Services in Bengaluru
  8. Android 16 Update Release Date, Eligible Devices and What to Expect
  9. Realme GT 7, Realme GT 7T Get Up to Rs. 6,000 Discount for a Limited Time in India
  10. Nothing Phone 3 Leaked Render Suggests Transparent Back Panel, Triple Rear Cameras, No Glyph Interface
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.