Unencrypted transmission of images in Tinder iOS app and Tinder Android app allows an attacker to extract private sensitive information by sniffing network traffic.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Link | Tags |
---|---|
https://www.wired.com/story/tinder-lack-of-encryption-lets-strangers-spy-on-swipes/ | press/media coverage third party advisory |
https://www.checkmarx.com/2018/01/23/tinder-someone-may-watching-swipe-2/ | third party advisory |