Skip to main content

Leapfrog tablets may have exposed your kid’s location data

Leapfrog, the popular kids’ tablet, has been found to have security vulnerabilities that could have let strangers capture young users’ location data and send them messages. 

A new report from CheckMarx, an application security testing company, revealed that the LeapPad Ultimate tablet used an insecure internet connection that could have revealed personal information like age, gender, and names about the children who own the product. An app for LeapPad Ultimate called Pet Chat was also found to potentially reveal a tablet’s location and information. 

The tablet is meant for children ages 3 to 6, and is supposed to be safer than an iPad or a Kindle since it doesn’t require Wi-Fi and can only download Leapfrog-made apps. Pet Chat is one such app that allows two or more Leapfrog users within 100 feet of each other to talk in a chat room using only preset phrases. 

CheckMarx found that by using WiGLE, a website that shows different wireless hot spots, a stranger could have discovered the locations of children using the Pet Chat app on Leapfrog because the app creates an ad hoc Wi-Fi connection. Leapfrog removed the Pet Chat app from stores in June, according to CheckMarx. Those with LeapPad devices older than three years may still have the Pet Chat app, and parents are being advised to uninstall the app manually. 

Another vulnerability threat was discovered in Leapfrog’s child-safe web browser known as LeapSearch. CheckMarx manipulated the browser into a “phishing version” that could lead attackers to Leapfrog owners’ credit card, parent, and child information. 

CheckMarx said that after it brought this information to the attention of Leapfrog, the company was quick to act in fixing or removing the vulnerable features. 

“We thank Checkmarx for bringing these security issues to our attention, as the safety of the children who use our products is a top priority. With the information they provided, we were able to take immediate actions to resolve the issues. Checkmarx has been helpful, ethical, and professional.  Cooperating with them has benefitted LeapFrog and our customers,” Mari Sunderland, the vice president of digital product management, told Checkmarx. 

As more children are using technology at younger ages, tech companies have had to rethink how child-friendly their platforms and services are. On July 22, Facebook alerted parents about a security flaw in its Messenger Kids app. The technical error, which has since been fixed, allowed children to communicate with users in group chats who hadn’t been approved by their parents. 

YouTube has also had its fair share of issues with child-friendly content, and the Federal Trade Commission (FTC) was investigating the platform about how it handles videos aimed at children. YouTube has been accused of failing to protect kids, particularly when its algorithm recommends or queues inappropriate videos. 

Digital Trends reached out to Leapfrog for comment but has not yet received a response. 

Editors' Recommendations

Allison Matyus
Former Digital Trends Contributor
Allison Matyus is a general news reporter at Digital Trends. She covers any and all tech news, including issues around social…
AMD’s canceled GPU could have crushed Nvidia
The AMD Radeon RX 7900 XTX graphics card.

For months now, we've been hearing rumors that AMD gave up on its best graphics card from the upcoming RDNA 4 lineup, and instead opted to target the midrange segment. However, that doesn't mean that such a GPU was never in the works. Data mining revealed that the card may indeed have been planned, and if it was ever released, it would've given Nvidia's RTX 4090 a run for its money.

The top GPU in question, commonly referred to as Navi 4C or Navi 4X, was spotted in some patch information for AMD's GFX12 lineup -- which appears to be a code name for RDNA 4. The data was then posted by Kepler_L2, a well-known hardware leaker, on Anandtech forums. What at first glance seems to be many lines of code actually reveals the specs of the reportedly canceled graphics card.

Read more
You’ll never guess what this YouTuber built into a PC this time
A woman stands next to a custom-built gaming PC with a coffee maker inside.

There are gaming PCs, and there are coffee makers -- and the two do not mix. After all, who would want boiling hot coffee inside their high-end gaming desktop? The idea alone makes me shiver, but Nerdforge's Martina was brave enough to come up with this project and create a fully custom-built PC that doesn't just run, but it also makes coffee at the press of a button.

Nerdforge is a YouTube channel run by a Norwegian couple, Martina and Hansi, who dabble in all sorts of innovative crafts. And it's safe to say that this falls under that category. The project started with an idea: What if, instead of having to get up to fetch a cup of coffee, you could have a coffee maker installed right inside your PC?

Read more
Watch Boston Dynamics’ dog-like robot don a dog suit and dance
Boston Dynamics' Spot robot dressed as a dog.

Meet Sparkles | Boston Dynamics

Boston Dynamics has shared a video of its dog-like Spot robot dancing in a dog costume.

Read more