logo

Fertility tracker Glow fixes bug that exposed users’ personal data

ID: c9596d46-ae71-5e44-b37a-0de8b9d2015f

STIX ID: report--c9596d46-ae71-5e44-b37a-0de8b9d2015f

Feed Name: TechCrunch Security News

Threat Score
70/100

Date Published: 2024-02-13

Date Updated: 2026-04-23

Author: Lorenzo Franceschi-Bicchierai

...
...

A security researcher discovered an IDOR vulnerability in Glow's developer API that allowed public access to personal data for approximately 25 million users, including names, self-reported age groups, location, internal user IDs, and user-uploaded images. The researcher reported the issue in October and Glow fixed the leak about a week later; the article notes prior privacy problems and a 2020 settlement related to Glow's handling of user health data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.