As more states continue to roll out their own health data-related privacy laws that do not fall under the federal regulatory umbrella of HIPAA, it is becoming more
Newly Patched Peloton API Flaws Exposed Users Private Data
May 20, 2021
Compliance
HealthInfoSec) • May 6, 2021
Photo: Peloton
Security researchers say API flaws could have exposed the private data of millions of Peloton fitness equipment online service users for months before they were recently patched.
The vulnerability issues emerged the same week that Peloton announced the voluntary recalls of two of its treadmills due to serious safety concerns.
In a blog posted Wednesday, security consultancy Pen Test Partners says that in January its researchers notified Peloton via its vulnerability disclosure site about flaws in an endpoint API.
The flaws could allow unauthenticated individuals to view sensitive information for all Peloton users, including snooping on live class statistics, even when users chose private mode settings for their account profiles, Pen Test Partners says.