“BOOM – the OTP is directly in the response, meaning anyone’s account can be accessed with just their phone number.”
Cerca’s login API returned the one-time code in its own response, so a phone number was enough to take over any account. Passport photos, sexual preferences, and messages were exposed. Its privacy policy promised industry-standard encryption. Users were never told.