App-connected sex toys are vulnerable to major security risks, leaving user emails vulnerable to hackers, after the firm failed to fix two security flaws.
Lovense is a marker of internet-connected sex toys with over 20 million users. The sex toys connect to the internet and bluetooth, where users can connect their devices together using an app. The company has tried to stay ahead of the curve technology-wise, as it integrated ChatGPT into its products in 2023.
However, when it comes to basic security hygiene, the company seems lacking.
Cybersecurity blogger BobDaHacker said that Lovense is exposing other people’s email addresses to other users of the apps. Though not directly exposed in the app, the use of a network analysis tool to look at the data transferring in and out of the app would reveal users email addresses when a user interacts with them.
BobDaHacker discovered that they could associate any Lovense username with their registered email address – this could expose any customer with an email address.
Using an XMPP roster and using a known username – which can often be made public for people’s work – can be exploited to return a real email address.
BobDaHacker has tested this out multiple times, saying that now, he can retrieve an email based off a username is less than a second.
Another vulnerability allowed BobDaHacker to take over any Lovense user’s account using just their email address. This secondary bug allows anyone to create authentication tokens without a password, which means a hacker can remotely control an account pretending to be the actual account holder with just the email address.
“Literally anyone could take over any account just by knowing the email address,” BobDaHacker said.
Recommended reading
- Are Sex Toys The New Hacking Frontier?
- Smart Devices Leave UK Households Vulnerable
- The Smart Devices Harvesting Your Data
This is a major issue for people’s privacy, especially webcam models who use these tools for work and share their usernames for tips and subscribers.
Upon discovering the security flaws, BobDaHacker has been through numerous back and forths with Lovense, after first notifying them of the bugs back in March.
While BobDaHacker recieved $3,000 via HackerOne, a bug bounty site, Lovense requested 14 months to fix the flaws. Typically, security research only grant organisations about three months to fix any identified flaws before they take their findings public.
In the same email saying the fix would take 14 months, Lovense explained that they opted not to adopt a fix that would take one month because they wanted to avoid requiring users to update their apps.
Lovense has since commented that there is currently “no evidence suggesting that any user data, including email addresses or account information, has been compromised or misused.”
The company also assured that “the email address exposure vulnerability has been fully resolved, and updates have been deployed to all users.”
The account takeover vulnerability identified in the bug bounty exercise by BobDaHacker has also been “fixed” according to Lovense.
Lovense also iterated that their proposed 14-month system reconstruction plan was a “comprehensive project,” and that reducing it to “a simple, ‘fixable in two days'” problem was “misleading.”
Lovense said that the company is “proud to be one of the earliest sex toy companies” to join the HackerOne programme in 2018, and that they “value the insights provided in the vulnerability disclosure report.”
“However, we must clarify that any accusations of neglect regarding user safety are unfounded.”
Lovense has urged all users to upgrade to the latest version to access all functions. “While those who do not upgrade will not face security risks, certain features will become unavailable.”





