Technology

Dating App ‘Raw’ Exposes Users’ Personal Data in Alarming Security Breach

2025-05-04

Author: Wei

In an unsettling turn of events, the dating app Raw, which recently unveiled a peculiar wearable device, has been caught exposing its users' personal information. This data breach included sensitive details like precise locations and other private information.

Raw promotes itself as an app dedicated to fostering "real and unfiltered love," much like BeReal, using both front and back cameras. However, it has now unintentionally become notorious for something far less romantic: the careless handling of its users’ data.

The app's new gadget, the Raw ring, ostensibly allows users to monitor their partners' locations, purportedly to catch any signs of infidelity. How this surveillance might lead to tumultuous relationships is a concern for another day. Meanwhile, the app's lack of essential digital security measures has inadvertently laid its users’ data bare.

TechCrunch illuminated the security flaws after conducting tests on the app. They discovered a chilling oversight: the app was publicly accessible, meaning anyone with a web browser could retrieve sensitive details like users' birth dates, display names, sexual orientations, and even specific street-level locations.

During their investigation, TechCrunch found that personal data streamed from Raw’s servers without any authentication checks, making it effortlessly obtainable. By merely adjusting an 11-digit identifier tied to a user, anyone could access another individual’s profile, including their precise location—an oversight known as Insecure Direct Object Reference (IDOR). This bug is particularly severe as it allows unauthorized access to sensitive user data due to insufficient security protocols.

Gizmodo reached out for a statement from Raw, and the company confirmed that they have since rectified these security issues as of Wednesday. Marina Anderson, co-founder of the Raw dating app, assured TechCrunch that all previously exposed endpoints have been secured and additional safeguards have been implemented to prevent future breaches. However, with the initial exposure of personal data, many users are left questioning the integrity of their online safety amid the pursuit of love.