From Home to Tech, CartKore Brings You the Best — Without Breaking the Bank

A Lovense security flaw may be letting people take over accounts without a password

Sex toy company Lovense is leaking the email addresses of its app users and allowing account takeovers without asking for a password, according to a security researcher. As reported by , BobDaHacker, who describes themself as an ethical hacker committed to exposing and reporting security vulnerabilities, published an in which they accuse Lovense of failing to fix a serious bug it was first made aware of in 2023.

According to the hacker (and later verified by TechCrunch), Lovense allows any username to be turned into their email address with the right know-how, a flaw they initially discovered after muting someone on the app. With their access to Lovense’s API, they were able to obtain the emails associated with any public username in less than a second when running the modified request process through an automated script. They noted that the vulnerable nature of these accounts is “especially bad for cam models” who use the Lovense platform for work, and may share their usernames for these purposes.

The researcher also realized that with a user’s email address (either one you already know or one obtained using the aforementioned disclosure bug), they could generate auth tokens that allowed them to take over the associated account without a password. This allegedly worked for the Lovense Chrome Extension and Lovense Connect app, as well as the company’s Cam101 and StreamMaster software — and even admin accounts.

BobDaHacker said they initially reported the bugs to Lovense with assistance from the sex tech hacking project in March 2025, and received $3,000 in total for flagging them via the HackerOne security platform. After a series of interactions with Lovense representatives, they were told in early June that the account takeover bug had been fixed during the previous month, which the researcher claims is not true. Regarding the email disclosure flaw, Lovense said in a printed by BobDaHacker that it could take up to 14 months to fix the issue, as a faster one-month fix would “require forcing all users to upgrade immediately,” which it said would “disrupt support for legacy versions.”

The researcher went on to say that they were contacted by a Twitter user who claimed to have found the same account takeover bug as far back as 2023, and were told shortly after reporting it to Lovense that the bug had been resolved, which wasn’t the case. They said a patch eventually fixed their method, which used an HTTP endpoint to convert a username into an email address, but that it wasn’t rolled out until early 2025. BobDaHacker said they had requested comment from Lovense but at the time of writing had not received one.

This isn’t the first time Lovense users have stumbled upon privacy concern bugs. In 2017, a Redditor that the Lovense app, which allows users to control their sex toys remotely, was recording audio without their consent and saving it to their phone. A commenter on the Reddit , who claimed to be a Lovense representative, called the recordings a “minor software bug” that affected the Android version of the app and said at the time that it had been fixed in an update.

Trending Products

- 5% Acer Chromebook 314 CB314-4H-C2UW L...
Original price was: $239.99.Current price is: $229.00.

Acer Chromebook 314 CB314-4H-C2UW L...

0
Add to compare
- 10% Sceptre 4K IPS 27″ 3840 x 216...
Original price was: $199.97.Current price is: $179.97.

Sceptre 4K IPS 27″ 3840 x 216...

0
Add to compare
- 32% SAMSUNG 32-Inch ViewFinity S7 (S70D...
Original price was: $399.99.Current price is: $270.99.

SAMSUNG 32-Inch ViewFinity S7 (S70D...

0
Add to compare
- 27% KEDIERS G8 Pre-Installed 6 × 120mm...
Original price was: $127.40.Current price is: $92.99.

KEDIERS G8 Pre-Installed 6 × 120mm...

0
Add to compare
- 26% HP 15.6″ Touchscreen Laptop, ...
Original price was: $828.24.Current price is: $609.00.

HP 15.6″ Touchscreen Laptop, ...

0
Add to compare
- 23% 15.6” Laptop computer 12GB DD...
Original price was: $311.99.Current price is: $239.99.

15.6” Laptop computer 12GB DD...

0
Add to compare
- 25% Thermaltake View 200 TG ARGB Mother...
Original price was: $106.39.Current price is: $79.99.

Thermaltake View 200 TG ARGB Mother...

0
Add to compare
- 33% Logitech MK345 Wireless Keyboard an...
Original price was: $59.59.Current price is: $39.99.

Logitech MK345 Wireless Keyboard an...

0
Add to compare
- 22% Logitech MK120 Wired Keyboard and M...
Original price was: $19.99.Current price is: $15.69.

Logitech MK120 Wired Keyboard and M...

0
Add to compare
- 38% NZXT H5 Stream Compact ATX Mid-Towe...
Original price was: $151.32.Current price is: $93.99.

NZXT H5 Stream Compact ATX Mid-Towe...

0
Add to compare
.

We will be happy to hear your thoughts

Leave a reply

CartKore
Logo
Register New Account
Compare items
  • Total (0)
Compare
0
Shopping cart