A security researcher discovered vulnerabilities in the Cerca dating app, including broken OTPs and open endpoints, which allowed access to personal information, passport data, and intimate messages. The researcher reported the issues to the Cerca team, who acknowledged the problems and promised to address them, but then failed to follow up or inform users. The vulnerabilities have since been patched, but the incident raises concerns about the app's security and the company's handling of the situation. The researcher published their findings to highlight the importance of security and responsible disclosure.