Tinder's vulnerability profile reflects a focused footprint around its mobile dating application, with the observed weakness centered on improper handling of sensitive data in transit. The recurring signal involves cleartext transmission issues, indicating a pattern of data-protection control gaps in the application layer. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tinder over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-6018CRITICAL Fixed sizes of HTTPS responses in Tinder iOS app and Tinder Android app allow an attacker to extract private sensitive information by sniffing network traffic. | Jan 24, 2018 | 9.1 | 29 | NO | NO |
CVE-2018-6017CRITICAL Unencrypted transmission of images in Tinder iOS app and Tinder Android app allows an attacker to extract private sensitive information by sniffing network traffic. | Jan 24, 2018 | 9.1 | 27 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tinder.
Media articles that mention a CVE ID that affects a product developed by Tinder — matched by CVE ID, not by vendor name.