6 May 2021

Software bug exposed Peloton users private account data


Software bug exposed Peloton users private account data

A flaw in Peloton’s online service exposed sensitive users' data, making it available to anyone on the internet, even if a profile was set to private, Jan Masters, a security researcher at Pen Test Partners, has found.

Peloton makes network-connected stationary bikes and treadmills and also provides users access to live real-time classes and sessions with a coach, as well as classes for treadmill, yoga, and outdoor running.

Masters discovered that he could make unauthenticated requests to Peloton’s application programming interface (API), for user account data without it checking whether the person was allowed to request it.

The exposed information included user IDs, instructor IDs, group membership, workout stats, gender and age, weight, and if a user is in the studio or not.

The researcher said he contacted Peloton over the API bug in January and promptly received a response acknowledging the issue, however, after that the company went silent. At the beginning of February Peloton silently issued a partial fix, which addressed the issue by making user data available only to authenticated Peloton users. The researchers then informed the company of the inadequate fix but again received no response. The issue was fixed in May after Pen Test Partners directly contacted a new Peloton’s CISO.

Back to the list

Latest Posts

US charges Samourai cryptomixer founders for laundering $100 million

US charges Samourai cryptomixer founders for laundering $100 million

The cryptocurrency mixer facilitated over $2 billion in illegal transactions.
25 April 2024
ArcaneDoor state-sponsored malware campaign strikes Cisco networking gear

ArcaneDoor state-sponsored malware campaign strikes Cisco networking gear

The attackers exploited two zero-day vulnerabilities in Cisco networking equipment.
25 April 2024
Iranian hackers exploit RMM tools to deliver malware

Iranian hackers exploit RMM tools to deliver malware

One of the aspects of MuddyWater's strategy involves exploiting Atera's free trial offers.
24 April 2024