Peloton fixes bug that reportedly exposed users' data and account information

Advertisement
Peloton fixes bug that reportedly exposed users' data and account information
Scott Heins/Getty Images
  • Peleton workout equipment previously had a bug that allowed users to access private account information.
  • The information included the user's gender, weight, birthday, age, workout statistics, and more.
  • Peleton confirmed to TechCrunch on Wednesday that the bug has been fixed.
Advertisement

Peloton has confirmed it fixed a bug that exposed users' private account data, according to TechCrunch.

The bug was first discovered by Jan Masters, a security researcher at Pen Test Partners, TechCrunch reported.

Masters found the breach by learning he could make unauthenticated requests to access someone's data through Peloton's programming interface. The bug exposed users' age, location, workout statistics, and weight.

Complimentary Tech Event
Transform talent with learning that works
Capability development is critical for businesses who want to push the envelope of innovation.Discover how business leaders are strategizing around building talent capabilities and empowering employee transformation.Know More

The researcher told TechCrunch that he reported the flaw on January 20, but the issue was only confirmed to be fixed after Peloton was contacted by TechCrunch.

The security flaws discovered in Peleton's equipment demonstrate the reasons that cybersecurity experts were wary of reports that President Joe Biden might bring his Peleton bike to the White House: the additional cameras, sensors, and microphones present in the device pose potential national security risks if hacked into and personal data is leaked.

Advertisement

The "Security and Compliance" page of Peleton's website notes that despite company efforts, security vulnerabilities may still exist in Peleton's products.

"No matter how much effort we put into system security, there can still be vulnerabilities present," the company website says.

News of the data bug came just before Peloton recalled its Tread+ running machine Wednesday amid reports that a child died and others were injured while it was operating. The recall sent Peleton's stock into a nosedive, falling more than 13% as of Wednesday afternoon.

Peloton fixes bug that reportedly exposed users' data and account informationPeloton fixes bug that reportedly exposed users' data and account informationPeloton fixes bug that reportedly exposed users' data and account informationPeloton fixes bug that reportedly exposed users' data and account informationPeloton fixes bug that reportedly exposed users' data and account informationPeloton fixes bug that reportedly exposed users' data and account informationPeloton fixes bug that reportedly exposed users' data and account informationPeloton fixes bug that reportedly exposed users' data and account informationPeloton fixes bug that reportedly exposed users' data and account informationPeloton fixes bug that reportedly exposed users' data and account informationPeloton fixes bug that reportedly exposed users' data and account informationPeloton fixes bug that reportedly exposed users' data and account informationPeloton fixes bug that reportedly exposed users' data and account informationPeloton fixes bug that reportedly exposed users' data and account informationPeloton fixes bug that reportedly exposed users' data and account informationPeloton fixes bug that reportedly exposed users' data and account informationPeloton fixes bug that reportedly exposed users' data and account informationPeloton fixes bug that reportedly exposed users' data and account informationPeloton fixes bug that reportedly exposed users' data and account informationPeloton fixes bug that reportedly exposed users' data and account informationPeloton fixes bug that reportedly exposed users' data and account informationPeloton fixes bug that reportedly exposed users' data and account informationPeloton fixes bug that reportedly exposed users' data and account informationPeloton fixes bug that reportedly exposed users' data and account informationPeloton fixes bug that reportedly exposed users' data and account informationPeloton fixes bug that reportedly exposed users' data and account informationPeloton fixes bug that reportedly exposed users' data and account informationPeloton fixes bug that reportedly exposed users' data and account informationPeloton fixes bug that reportedly exposed users' data and account information
{{}}