Dating App Bug Leaves 1.5M Sensitive Photos 'Publicly Accessible to Anyone' (2025)

Over 1.5 million user photos collected by dating apps available on the iOS App Store, mainly catering to the LGBTQ+, BDSM, and “sugar dating” communities, have been compromised, according to a new report.

Data that was left "publicly accessible to anyone" included explicit content sent between users via direct messaging, as well as profile photos, public posts, profile verification images, and photos removed due to rule violations, Cybernews reports. Affected apps include SM People, Chica, Translove, Pink, and Brish. All the apps were developed by M.A.D. Mobile Apps Developers, a UK-based company.

Cybernews says its researchers "downloaded 156,000 iOS apps, around 8% of all apps on the Apple Store [and] discovered that app developers are leaving plaintext credentials in the application code accessible to anyone."

In the case of BDSM People, researchers think this app alone leaked 541,000 private images, including 90,000 from users' direct messages. Meanwhile, the sugar dating app Chica is thought to have leaked 133,000 photos, including private chats.

M.A.D. Mobile Apps Developers have yet to officially comment on the news.

Cybernews's research suggests that this type of data leak could put users at significant risk further down the road. “With homosexuality being illegal in some countries, the leak could put app users at high risk of persecution,” said the report, emphasizing how sensitive images of this type can be used for extortion, social engineering, and attempts to damage a person’s professional reputation.

Researchers outlined how the necessary credentials to access sensitive data were stored in the code of the apps themselves, which could then have been used to find images stored externally in other locations (all the dating apps shared the same basic architecture). Even if the images didn't have names or registration emails attached, the researchers noted how techniques like reverse image search could be used to identify the people in the pictures.

Recommended by Our Editors

Creator of HaveIBeenPwned Data Breach Site Falls for Phishing Email

Hewlett Packard Enterprise Investigates Possible Breach, Source Code Theft

Dating app breaches can have big consequences for those involved. Ashley Madison, a dating site for extramarital affairs, was hit by a data breach in 2015, which resulted in the personal data of 32 million users being leaked by a hacking group. As a result, several cases of blackmail and extortion were reported, and two suicides were even linked to the case.

The LGBTQ+ community has been hit hard before by data leaks. In 2021, it was revealed that the gay dating app Grindr shared sensitive user data, including HIV status and GPS location data, with third-party companies back in 2018. In 2023, some mobile tracking data from Grindr waspurchased by a conservative Catholic group in Colorado, which used it to identify gay priests across the US.

Get Our Best Stories!

Dating App Bug Leaves 1.5M Sensitive Photos 'Publicly Accessible to Anyone' (4)

Dating App Bug Leaves 1.5M Sensitive Photos 'Publicly Accessible to Anyone' (5)

Stay Safe With the Latest Security News and Updates

Sign up for our SecurityWatch newsletter for our most important privacy and security stories delivered right to your inbox.

By clicking Sign Me Up, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.

Thanks for signing up!

Your subscription has been confirmed. Keep an eye on your inbox!

About Will McCurdy

Contributor

I’m a reporter covering weekend news. Before joining PCMag in 2024, I picked up bylines in BBC News, The Guardian, The Times of London, The Daily Beast, Vice, Slate, Fast Company, The Evening Standard, The i, TechRadar, and Decrypt Media.

I’ve been a PC gamer since you had to install games from multiple CD-ROMs by hand. As a reporter, I’m passionate about the intersection of tech and human lives. I’ve covered everything from crypto scandals to the art world, as well as conspiracy theories, UK politics, and Russia and foreign affairs.

Read Will's full bio

Read the latest from Will McCurdy

  • Zuckerberg-Funded Elementary School for Low-Income Kids to Shut Down
  • Report: Russian Nuclear-Linked Satellite 'Spinning Uncontrollably'
  • Trump-Appointed Atty: Wikipedia Allows Foreign Actors to 'Spread Propaganda'
  • PSA: Google Ending Support for Early Gen Nest Learning Thermostats
  • Yahoo Joins OpenAI on List of Suitors for Google Chrome
  • More from Will McCurdy
Dating App Bug Leaves 1.5M Sensitive Photos 'Publicly Accessible to Anyone' (2025)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Zonia Mosciski DO

Last Updated:

Views: 5719

Rating: 4 / 5 (71 voted)

Reviews: 86% of readers found this page helpful

Author information

Name: Zonia Mosciski DO

Birthday: 1996-05-16

Address: Suite 228 919 Deana Ford, Lake Meridithberg, NE 60017-4257

Phone: +2613987384138

Job: Chief Retail Officer

Hobby: Tai chi, Dowsing, Poi, Letterboxing, Watching movies, Video gaming, Singing

Introduction: My name is Zonia Mosciski DO, I am a enchanting, joyous, lovely, successful, hilarious, tender, outstanding person who loves writing and wants to share my knowledge and understanding with you.