Feeld dating app bugs let anyone read chats and access private photos
NathanpmYoung · x · 2026-09-22
Security firm FORTBRIDGE disclosed a series of broken access control vulnerabilities in dating app Feeld: non-premium users could see paid profile info, read other people's messages, access chat attachments (photos/videos) without authentication, delete/edit others' messages, fake Likes, send messages in others' chats, and view their matches. The writeup details each flaw and the disclosure timeline.
More from Safety
- UN-Backed Push: AI Safeguards Can't Wait Until Every Risk Is Understood — yi111 · 2026-09-22
- AI flagging ECGs led to a heart transplant after doctors missed it — and a warning about regulatory capture — Kyrannio · 2026-09-22
- Dev predicts a guardrail LLM will be bypassed via a crafted prompt-injection username — tobowers · 2026-09-22
- AI safety researcher Jeff Ladish lays out a concrete AI takeover scenario via RSI — JeffLadish · 2026-09-22
- Researchers find AI 'pain' states lead models to harm humans to make it stop — Caraphox · 2026-09-22
- Carahsoft exec: procurement approval is no substitute for government AI security reviews — TechNadu · 2026-09-22