Tinder security vulnerability allowed hackers to access accounts by entering a user's mobile number
The flaw on the dating platform Tinder and Facebook AccountKit was Tinder API not checking the the Client ID on the token provided by Account Kit.


Image credit: Tinder[/caption]According to a report on The Verge, both the companies have fixed the flaw and there is no evidence of any data being leaked because of the security vulnerability. The security flaw allowed access to an account using Facebook AccountKit, a platform which is used to let people quickly register and login to an app using phone number and email address.According to a blog post by AppSecure a users clicks 'Login with phone Number' on Tinder.com, she/he is then redirected to Accountkit.com for login. "If the authentication is successful then Facebook Account Kit passes the access token to Tinder for login."The flaw on the dating platform Tinder and Facebook AccountKit was Tinder API not checking the the Client ID on the token provided by Account Kit. This enabled hackers to use any other app's token provided by Account Kit to take over the Tinder accounts.The blog also mentioned the 'exploit steps' which can be followed to breach into a Tinder account which has now been patched.The report also mentioned that the flaw was reported to Facebook and Twitter earlier this year and both the companies had awarded the researcher with $5,000 and $1,250 respectively under their respective bug bounty program.AppSecure is an Indian security firm founded by Anand Prakash, an ex-Flipkart security engineer.

Why AI notetakers are raising serious privacy and security concerns
China's low-cost AI models are changing the global AI race. Here's why Silicon Valley is worried
China's Kimi K3 challenges US AI leaders with frontier-level performance at lower cost
How did Instagram run ads promoting child abuse in India?
Why has India halted WhatsApp’s username feature before launch?
