Alleged Grindr Security Flaw Exposes Exact Location Data, Endangers Users

Advertisement
By Jamshed Avari | Updated: 20 August 2014 19:34 IST

An unknown person has been sending thousands of unsolicited messages to Grindr users in countries known to be hostile to LGBT citizens, warning them of a security flaw that could allow anyone with a bit of know-how to determine their exact location. The app is widely used by gay and bisexual men to meet each other discretely, and displays profiles of its users based on proximity.

The anonymous spammer, who is presumably acting altruistically, includes links to a Twitter account, YouTube video and Pastebin text dump, which contain more information. Heor she  claims to have used a secondary flaw to be able to send messages to over 100,000 users in 70 countries with anti-gay laws. The messages and posts express concern that Grindr users might be targeted, persecuted or even murdered. Homosexuality is punishable by death in several countries and violence against LGBT people and those who support them is routine and even encouraged in many places, which makes users extremely vulnerable.

According to the Pastebin dump, "officials at Grindr have been informed several times within the past months about these issues, which would seem to imply that the concept of 'social responsibility' is lost upon Grindr" (sic). "Knowing that Grindr-Users in countries such as these are being put unnecessarily at a high risk should be reason enough for Grindr to change its system," the author continues.

Advertisement

The location data is allegedly so accurate that someone exploiting the flaw would be able to tell "if you were using Grindr in the bathroom or on the couch". While the app only shows users the distance between them and other users, specific location data can be extrapolated by querying Grindr's servers from three different places and triangulating the information received. This process can also be automated using commonly available tools, and the resulting coordinates can be overlaid on a map.

Advertisement

The flaw arises from the fact that anyone can query Grindr's servers using standard JSON (JavaScript Object Notation) without needing to be authenticated. The server's response will contain whatever information users have added to their profiles, potentially including a photo, text description, age, ethnicity, body type, time last seen online, and relationship status.

Users can choose not to show their location to other users. If this flag is set, the JSON response will not contain location data. The YouTube link included in the anonymous messages and Twitter account leads to a video demonstrating the process in several parts of the world. With a single click, user profiles are displayed as pins on a map.

Advertisement

The second security risk is that message senders can be spoofed, and users can be impersonated. The Pastebin dump contains specific instructions including details of Grindr's messaging protocols and server addresses. This is how the unknown whistleblower has been sending out hundreds of thousands of messages.

NDTV Gadgets is in possession of screenshots of these messages which reached a user in India. The first message is a screenshot of the map in the video with a blurred profile marker, and superimposed text that reads "Using geo-based apps like Grindr allow other individuals in locating you. It is your own risk to use such apps in your country as anti-gay law has been applied." (sic). Grindr currently claims to have over five million active monthly users worldwide.

Advertisement

Earlier this year, a man was arrested in Lahore after murdering three men he had arranged to meet through Manjam, a similar social networking platform, in order to "send a message" about what he considered "spreading evil in society".

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Nothing Announces Offers on Phones, Wearables During Flipkart Sale
  2. Oppo F31 Series Launched With 7,000mAh Battery: Check Price, Features
  3. Samsung Galaxy S25 FE With 50-Megapixel Camera Launched in India: See Price
  4. Vivo Y31 Series With 6,500mAh Battery Launched in India: See Price
  5. Xiaomi 17 Pro Max Tipped to Come With a Secondary Display
  6. iOS 26 Update for iPhone Releases Today: Everything You Need to Know
  7. Realme P3 Lite 5G With 6,000mAh Battery Launched in India at This Price
  8. iOS 26 Releases Today: Check Out the Notable Features
  9. Nothing Phone 3 Price Will Drop to Rs 34,999 on Flipkart, But There's a Catch
  10. Flipkart Big Billion Days Sale: Discounts on Motorola Phones Announced
  1. Samsung Galaxy S25 FE Launched in India With 6.7-Inch AMOLED Screen, 50-Megapixel Camera: Price, Features
  2. iPhone 18 Series Tipped to Feature Smaller Dynamic Island, Might Launch Without Under-Display Face ID
  3. OnePlus 15 Leaked Image Hints at Redesigned Camera Module, Three Colourways
  4. Xiaomi 17 Pro Max Leaked Image Reveals Rear Display in a Nod to the 11 Ultra Ahead of September Debut
  5. Treasure Hunters Season 1 Now Streaming on JioHotstar: Everything You Need to Know
  6. London Stock Exchange Completes First Blockchain-Powered Fundraising via DMI Platform
  7. Zepto Fastest Sale Ever: Apple AirPods 4 Price Drops to Rs 9,999; Check Top Deals on Electronics, Accessories
  8. War 2 OTT Release Date Reportedly Revealed Online: When and Where to Watch it Online?
  9. MeitY Proposes 20-Year Tax Holiday for Data Centres to Boost Investment: Report
  10. Resident Evil Requiem, Resident Evil 7: Biohazard and Resident Evil Village Are Coming to Switch 2 Next Year
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.