Privacy flaw in top dating apps could have revealed user location down to 2 metres


Researchers have identified a loophole which allowed for ‘trilateration’ in popular dating apps including Bumble, Hinge, Grindr, Happn, Badoo, and Hily.
The team from Belgium’s KU Leuven University specifically used a technique known as oracle trilateration’ to pinpoint a user’s location down to two metres. This took a profile’s displayed location as a rough estimate, then by moving incrementally away in three different directions until the profile is out of range, revealed the exact location.
Trilateration is a technique used to determine an exact location using three points to gauge the distance to the object, then calculating the intersection to find the target location.
Dating app risks
Sensitive information being available to potentially malicious actors poses a threat to app users on multiple levels, researcher Karel Dhondt explained.
“Given that it’s related to dating, which really gets to people’s emotions and feelings, any privacy leaks or dangers are really exacerbated,” Dhondt said, “If people are hurt, they may want to hurt back. That’s why it’s important that people’s privacy and safety is well-maintained by these apps”.
Researchers also uncovered API (Application Programming Interface) leaks that could reveal personal data to an attacker, especially sensitive information such as user’s likes or preferences. All 15 apps studied were found to have some form of API leak.
A feature or a bug?
Most of the apps studied have since closed the gap and corrected this glitch by rounding the coordinates up by three decimal places to make them less precise. Grindr has allowed location sharing up to 111 metres, and explained that their location sharing practices are deliberate.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
“For many of our users, Grindr is their only form of connection to the LGBTQ+ community, and the proximity Grindr offers to this community is paramount in providing the ability to interact with those closest to them,” Grindr’s Chief privacy officer Kelly Peterson Miranda stated.
It is worth noting that in countries where homoesexual activity is illegal, this practice could prove to be particularly serious. Grindr insists that users are in control of the location information they provide.
Via TechCrunch
More from TechRadar Pro
Researchers have identified a loophole which allowed for ‘trilateration’ in popular dating apps including Bumble, Hinge, Grindr, Happn, Badoo, and Hily. The team from Belgium’s KU Leuven University specifically used a technique known as oracle trilateration’ to pinpoint a user’s location down to two metres. This took a profile’s displayed…
Recent Posts
- Grok blocked results saying Musk and Trump “spread misinformation”
- A GPU or a CPU with 4TB HBM-class memory? Nope, you’re not dreaming, Sandisk is working on such a monstrous product
- The Space Force shares a photo of Earth taken by the X-37B space plane
- Elon Musk claims federal employees have 48 hours to explain recent work or resign
- xAI could sign a $5 billion deal with Dell for thousands of servers with Nvidia’s GB200 Blackwell AI GPU accelerators
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010