Skip to main content

Leapfrog tablets may have exposed your kid’s location data

Leapfrog, the popular kids’ tablet, has been found to have security vulnerabilities that could have let strangers capture young users’ location data and send them messages. 

A new report from CheckMarx, an application security testing company, revealed that the LeapPad Ultimate tablet used an insecure internet connection that could have revealed personal information like age, gender, and names about the children who own the product. An app for LeapPad Ultimate called Pet Chat was also found to potentially reveal a tablet’s location and information. 

Recommended Videos

The tablet is meant for children ages 3 to 6, and is supposed to be safer than an iPad or a Kindle since it doesn’t require Wi-Fi and can only download Leapfrog-made apps. Pet Chat is one such app that allows two or more Leapfrog users within 100 feet of each other to talk in a chat room using only preset phrases. 

Please enable Javascript to view this content

CheckMarx found that by using WiGLE, a website that shows different wireless hot spots, a stranger could have discovered the locations of children using the Pet Chat app on Leapfrog because the app creates an ad hoc Wi-Fi connection. Leapfrog removed the Pet Chat app from stores in June, according to CheckMarx. Those with LeapPad devices older than three years may still have the Pet Chat app, and parents are being advised to uninstall the app manually. 

Another vulnerability threat was discovered in Leapfrog’s child-safe web browser known as LeapSearch. CheckMarx manipulated the browser into a “phishing version” that could lead attackers to Leapfrog owners’ credit card, parent, and child information. 

CheckMarx said that after it brought this information to the attention of Leapfrog, the company was quick to act in fixing or removing the vulnerable features. 

“We thank Checkmarx for bringing these security issues to our attention, as the safety of the children who use our products is a top priority. With the information they provided, we were able to take immediate actions to resolve the issues. Checkmarx has been helpful, ethical, and professional.  Cooperating with them has benefitted LeapFrog and our customers,” Mari Sunderland, the vice president of digital product management, told Checkmarx. 

As more children are using technology at younger ages, tech companies have had to rethink how child-friendly their platforms and services are. On July 22, Facebook alerted parents about a security flaw in its Messenger Kids app. The technical error, which has since been fixed, allowed children to communicate with users in group chats who hadn’t been approved by their parents. 

YouTube has also had its fair share of issues with child-friendly content, and the Federal Trade Commission (FTC) was investigating the platform about how it handles videos aimed at children. YouTube has been accused of failing to protect kids, particularly when its algorithm recommends or queues inappropriate videos. 

Digital Trends reached out to Leapfrog for comment but has not yet received a response. 

Allison Matyus
Former Digital Trends Contributor
Allison Matyus is a general news reporter at Digital Trends. She covers any and all tech news, including issues around social…
Microsoft just gave you a major reason to ditch Chrome
The Microsoft Edge browser on a flat surface.

Microsoft has introduced a new RAM control feature in Edge, allowing users to cap memory usage to prevent slowdowns. Now available in the stable version, this setting can be enabled in the browser's performance section, as reported by Windows Latest.

In the resource control panel, you'll see a slider that you can adjust to let Edge use as little as 1GB or as much as 31GB. You can set the cap to apply when gaming or at all times. You can adjust this setting anytime. If you put the slider all the way to the right, the Edge browser will show "no set limit," but if you move the slider anywhere else, a current limit will be displayed. The RAM control feature might not significantly improve your gaming experience, but every little bit helps.

Read more
Hackers are using AI to breach systems faster than ever
A person using a laptop with a set of code seen on the display.

AI is helping hackers breach systems faster than ever and in under an hour, according to new research from ReliaQuest. The report also indicates that hackers are shifting from ransomware to data theft, making attacks harder to detect and defend against. Phone-based and phishing scams are also rising, making businesses rethink their security strategies to protect sensitive information.

The report found that hackers are moving away from ransomware and focusing on selling stolen data rather than demanding ransoms, as it is more profitable. 80% of breaches involve data theft, while only 20% include data encryption. This change implies companies are less likely to pay the ransom, as only around 7% recover their data. Phishing is currently the top way hackers steal data, with 30% of attacks including credentials theft. As attackers use AI, it only takes them four hours to steal the data and six hours to encrypt it.

Read more
Microsoft’s testing a new way to make Copilot unavoidable
Microsoft's AI Copilot being used in various Microsoft Office apps.

Microsoft is at it again, trying to "encourage" users to use Copilot by testing an option that automatically opens the Copilot pane in Edge, as @Leopeva64 spotted (via MSPowerUser). The Copilot pane hides when you switch tabs or open favorites, but it signals Microsoft's push to integrate AI deeply into Edge. The software giant is also introducing a new "share" button for Copilot to transmit an AI chat link and a machine-learning-powered autofill option for Android users.

Microsoft is testing the auto-open feature for Copilot in Edge Canary new tabs, but you can also turn it off in settings. Earlier this month, the feature was not fully functional. Now, nothing happens if you hover over the Copilot button, so you must click it instead.

Read more