Researchers: vulnerabilities in Badoo, Bumble, Grindr, happn, Hinge, and Hily let malicious users pinpoint locations to two meters; the apps fixed the issue
A group of researchers said they found that vulnerabilities in the design of some dating apps, including the popular Bumble and Hinge … Mastodon: @lorenzofb@infosec.exchange and @obrien_kat@mastodon.world . Forums: r/technology Mastodon: Lorenzo Franceschi-Bicchierai / @lorenzofb@infosec … : NEW: Researchers found that it was possible to pinpoint the location of Bumble and Hinge users down to 2 meters. — That was thanks to a design flaw in the “filters” feature, where the apps used the exact location of a victim. A stalker could have abused this flaw by spoofing their location multiple times in order to be able to calculate the victim's location. … @obrien_kat@mastodon.world : This is frightening on how close someone could narrow down location on a user on popular dating apps like Bumble and Tinder. Down to meters. Said to be fixed. — https://techcrunch.com/... #tech #privacy #data Forums: r/technology : Bumble and Hinge allowed stalkers to pinpoint users' locations down to 2 meters, researchers say
Context & Ripple Effects
This is a recurrence of a long-running dating-app privacy problem: earlier research showed that public APIs could reveal Grindr users’ locations, and a 2019 location-disclosure finding demonstrated that knowing a username could be enough to derive location data.
The new report matters because it identifies the exposure in a product-design layer—the location-aware filtering mechanism—rather than solely in an account-data breach. It also follows a prior Bumble data-exposure flaw, reinforcing that privacy risk can emerge from multiple app surfaces.
First-order effects
- The affected apps’ fixes close the reported route by which a malicious user could repeatedly spoof location and calculate another user’s position to roughly two meters.
- Users of Badoo, Bumble, Grindr, happn, Hinge, and Hily receive an immediate reduction in stalking risk from that specific filter-design weakness.
Second-order effects
- Dating-app operators have a clear reason to test nearby-user, distance, search, and filtering features for inference attacks—not just for direct leakage of location fields.
- Privacy and security teams will need to treat the precision of location-derived outputs as sensitive even when an app does not explicitly display a user’s coordinates.
Third-order effects
- Repeated location-inference findings suggest that meaningful location privacy depends on product architecture and adversarial testing, not only on permissions screens or stated data policies.
- If platforms adopt that discipline consistently, proximity features may increasingly be designed around coarser outputs and tighter limits on repeated queries; the corpus does not establish whether this will occur across the sector.
The trend: Dating platforms are being pushed to redesign proximity features around resistance to location inference, as recurring research exposes how seemingly limited location signals can be combined into precise tracking.