Cameo is leaking user data and private celebrity videos you paid for

(Image credit: Cameo)

Cameo, a popular app that lets you pay celebrities to record short shout-out videos for you, is overrun with security flaws that the service's customers and famous users probably don't know about. 

According to a report from Vice, Cameo has exposed a sum of user data because of a "misconfiguration" in its app. The compromised information includes customer's emails and in-app messages. Hashed and salted passwords and phone numbers are allegedly revealed too.

On the celebrity side of Cameo's business, a researcher told Vice they discovered that Cameo videos that are meant to be private can actually be found and downloaded by anyone on the app. 

Motherboard, Vice's technology vertical, even wrote code capable of identifying private videos filmed by the likes of rapper Snoop Dogg and comedian Michael Rapaport. All these "private" videos were, in fact, accessible.

It seems Cameo's transactions are designed to be as simple as possible, relying on basic, sendable links to fulfill requests. Anyone with a link for a pending Cameo videos can amend what the chosen celebrity is being asked to speak about, or even cancel the request.

Motherboard editor-in-chief Jason Koebler requested a Cameo video from comedian Gilbert Gottfried to verify its findings. Koebler set the video to private, yet a Motherboard staff writer was able to view Gottfried's message (which intentionally concerns cybersecurity) and download it.

It gets sketchier. Cameo hosts its privacy policy on a Google Doc, while Cameo creators use a messaging app called Telegram to send completed videos. 

The researcher who spoke to Vice said the app's code includes credentials that let anyone access Cameo's backend infrastructure and access user data. Motherboard believes these credentials may have been exposed for two years.

Cameo problem 'promptly fixed'

Cameo has since acknowledged the data-security scare. The company said it "promptly fixed the issue" and didn't find evidence that anyone other than the researcher had used the vulnerability. 

For safe measure, anyone who has a Cameo account should change their password. Just because Cameo hashes and salts passwords (i.e., stores them in an encrypted form on its servers) doesn't mean your credentials are safe. 

Given the dicey infrastructure mentioned above, it's certainly possible the company uses an outdated or weak password hashing algorithm.

As for the question of private videos, Cameo clarified its policies: "A Cameo being classified as ‘private’ pertains to a specific Cameo not being posted on the Cameo platform (meaning the talent’s profiles or other pages). 

"Cameo was designed for people to gift and share personalized videos from their favorite talent between friends and family. Both public and private Cameos are intended to be shared socially."

Kate Kozuch

Kate Kozuch is the managing editor of social and video at Tom’s Guide. She writes about smartwatches, TVs, audio devices, and some cooking appliances, too. Kate appears on Fox News to talk tech trends and runs the Tom's Guide TikTok account, which you should be following if you don't already. When she’s not filming tech videos, you can find her taking up a new sport, mastering the NYT Crossword or channeling her inner celebrity chef.

Latest in Online Security
23andME box
23andMe has declared bankruptcy — here's how to delete your data now
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
A man filing his taxes electronically on a laptop
AI-powered tax scams are here - how to stay safe from deepfakes, phishing and more this tax season
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Latest in News
Apple Watch Ultra 2
Apple Watch Ultra 3 just tipped for two major upgrades
NYTimes Connections
NYT Connections today hints and answers — Tuesday, March 25 (#653)
A first look at Amazon's Fallout TV series coming to Prime Video
‘Fallout’ season 3 plans are reportedly being made — while season 2 is still filming
Surface Laptop 7 from the front
Amazon just gave Surface Laptop 7 a 'frequently returned' label — here's what's going on
New emojis with iOS 18.4 beta release.
iOS 18.4 beta brings 8 new emoji to your iPhone — here's all the new options
23andME box
23andMe has declared bankruptcy — here's how to delete your data now