September 29, 2026
Fitness Apps & The Hidden Security Risks
Real-world bug bounty findings on how fitness apps can be turned into spyware
By Vivek Maurya
4 min read
With obesity becoming a worldwide issue, and in fact, an epidemic in several countries, health and fitness have received increasing attention in recent years. At the same time, fitness apps and trackers have gained a lot of traction and are no longer confined to only fitness freaks.
People are using fitness apps, smartwatches, and several other devices to keep track of their workouts. These devices generally share the data with a designated app for long-term storage purposes. While this is very convenient, these apps also have access to sensitive information, such as location data, to provide GPS navigation for outdoor sports.
Another notable feature we find across many such apps is the ability to integrate with a number of partner apps. Allowing integration with partner apps is in itself a very convenient feature. Different apps have a designated specialization, allowing users to get benefits from them. Based on their role, the data transmission can be unidirectional or bidirectional.
From a security point of view, the integration logic is very interesting for two reasons:
- Any developer mistake in the integration logic means the data can be shared with the wrong entity.
- One app may be secure, but if the partner app isn't, the user's data is in danger simply because they chose the wrong partner app.
The direction of data flow matters, especially when sensitive data is involved. For example, when the app only receives data from the partner app, the risk is significantly lower than when it is sending the data as well.
However, just because the data is received doesn't necessarily mean the issue will be harmless. For example, many apps allow users to share their data with the community. An attacker could store data containing a GPS location of a shady or sensitive place where the victim was never actually present. When the victim's app receives this data, it may be displayed to the community as the victim's own activity, potentially damaging their reputation. Hence, what matters is not only the direction in which data flows, but also which data is exposed and how an attacker's creativity can exploit it
REAL WORLD FINDINGS
The following are two examples I came across while testing these integrations.
While testing a renowned app through their private program on Bugcrowd, I found an integration flaw that basically allowed me to gain access to any user's precise GPS location, among other things, without any user interaction. The vulnerability was considered serious, and I was rewarded a $1250 bounty.
During another test, I came across a flaw in ZEPP's integration logic. For those unfamiliar with the ecosystem, Amazfit is a wearable brand, and its watches use the ZEPP app to sync and manage the data collected by the watch. Being an Amazfit user myself, I was able to test this integration practically. The ZEPP app also doesn't use SSL pinning, saving me the hassle of dealing with SSL pinning bypass.
ZEPP was using predictable user IDs in the "state" parameter. By changing the ID to another user's ID, it was possible to connect that user's ZEPP account to the attacker's partner app.
For readers who aren't familiar, in OAuth-type flows, the "state" parameter acts as a CSRF protection mechanism. The value is generally expected to be unpredictable and tied to the initiating session. Using a predictable user ID poses the following risks:
- The user ID is 10 digits long; however, it's not completely random. I have two accounts with the first seven digits being the same. Hence, it's possible to find a number of users by modifying only the last three digits.
- Since the user ID is persistent, by doing some basic OSINT, it's possible to find a large number of real users' IDs online. I am not mentioning the steps here to avoid real user data being targeted.
Since the app sends data to their partner app and does not merely receive data, this is a very serious issue. An attacker can potentially connect their app to another ZEPP user's account.
Say an Amazfit user goes for an outdoor run and syncs their watch data with the ZEPP app. As soon as the data is synced with ZEPP, it is also synced with the attacker's partner app, exposing their location along with other details and effectively enabling the attacker to spy on their victim.
I confirmed the issue with different partner apps such as Strava and Adidas Running.
I reported the issue on June 11, 2026, and did not receive any response. I sent a couple of follow-ups with no success.
After more than 90 days without a response, I decided to move on. Hence, the issue is still unresolved at the time of posting this article.
CAUTION FROM USERS
As we saw, a vulnerability in fitness apps can allow attackers to spy on users. Users must therefore take caution about which apps they are using.
- Use reputable apps. No app can be guaranteed to be secure. But a reputable app has a lot to lose from bad security publicity, giving them more incentive to take security seriously.
- When integrating with partner apps, consider whether the app only receives data from the partner app or sends data to it too. The risk when the data is only received is much lower than when the data is sent too.
- Users should also review which third-party applications they have connected to their fitness apps and revoke integrations they no longer use, especially when those integrations have access to sensitive data such as location or workout history.
CONCLUSION
There are lots of emerging apps in the fitness industry. As connected fitness apps and devices continue to become more popular, many applications still lack designated bug bounty or vulnerability disclosure programs on reputable platforms, making testing of those applications difficult.
It is simply very tiring to keep sending follow-up emails without any responses, especially in today's scenario where the rise of AI-generated submissions has disrupted even the biggest and most reputable bug bounty programs.
I expect situations to improve a lot in the near future, making this one of the most interesting areas to explore for bug hunters and security researchers.
However, until then, users must be extra cautious about which apps they are installing, integrating, and what data they are sharing. Who knows, maybe someone reading this is being surveilled by someone without knowing it, simply because of the choice of apps they have installed.