← IoT Privacy Database

Lovense Connected Toy

Lovense (Shenzhen Lianwan Technology) · Intimate Device

✓ Reviewed

7.7Surveillance
Index
Policy — what its policy permitsD
Evidence — what research provesF

Its account system let anyone convert a public username into a user's email in under a second and take over accounts with just an email, exposing roughly 11.37 million users in 2025.

Why this rating

Lovense's account system let anyone convert a public username into a user's email in under a second, exposing roughly 11.37 million accounts to takeover in 2025 — a critical security failure affecting a highly sensitive device category.

What it is

Manufacturer
Lovense (Shenzhen Lianwan Technology)
Category
Intimate Device
Model years
2011-present
Market status
Current
Companion app
Lovense Remote

The evidence 5

Independent research, regulatory action, lawsuits, breaches and journalism about this device — the "what actually happens" axis. Each links to its source.

  1. Security advisory · ThaiCERT · 2025-08-05

    ThaiCERT security advisory summarizing the Lovense account-takeover vulnerabilities and their potential impact on roughly 11.37 million accounts.

    Why it matters here: ThaiCERT advisory quantifying the ~11.37 million affected accounts.

  2. Security advisory · bobdahacker.com · 2025-08-01

    Independent researcher follow-up showing the Lovense email-leak vulnerability remained exploitable after the initial disclosure.

    Why it matters here: Follow-up confirming the vulnerability remained exploitable.

  3. Security advisory · TechCrunch · 2025-07-29

    TechCrunch reports a vulnerability let anyone convert a Lovense user's public username into their private email address in under a second, enabling account takeover.

    Why it matters here: TechCrunch's direct report on the Lovense email-exposure and account-takeover vulnerability.

  4. Journalism · The Verge · 2025-07-29

    The Verge's coverage of the Lovense app vulnerability exposing user email addresses and enabling account hijacking.

    Why it matters here: The Verge's coverage of the Lovense vulnerability.

  5. Journalism · Vice · 2025-07-29

    Vice's reporting on the scale of the Lovense email-exposure vulnerability and the company's slow initial response.

    Why it matters here: Vice's reporting on the scale of the exposure and slow company response.

Descriptive, cited, not legal advice; ratings are versioned and corrections create a new version. Data from the IoT Info Grabber DB research project, CC BY-SA 4.0.

← Back to the IoT Privacy Database