
Both Twitter and Facebookhave confirmed that millions of users' personal information have been leaked to malicious actors by apps . This information includes names, gender, emails, usernames and possibly their most recent tweets.
As announced on Monday: “We recently received a report of a malicious mobile software development kit (SDK) maintained by oneAudience. The SDK was hidden in apps on the Google Play Store and can “exploit a vulnerability in the device” to expose users’ personal data to third-party developers.”
Many apps often request access to users' social media accounts to provide features like in-game leaderboards and the ability to share achievements. However, apps containing this exploit kit give hackers access to more information than users have agreed to.
"While we have no evidence to suggest it was used to take control of a Twitter account, it is possible that someone could do so," Twitter said.
Fortunately, there is no indication that iOS users were affected. However, Android were not as lucky, as many of their accounts were affected.
Twitter has notified Google and Apple and will also notify users who may have been affected. Unfortunately, there's not much a user can do other than delete apps they don't use and hope they haven't been affected.
And Facebook users were affected by the oneAudience SDK, as well as a similar SDK from MobiBurn.
The company will also notify potentially affected users, who number 9.5 million. In a statement to CNBC, Facebook claimed it has removed the dangerous apps.
In response, oneAudience released a statement on Monday saying it would immediately halt its SDK, though it noted that it had already released an update to prevent the data collection. “This data was never intended to be collected, was never added to our database, and was never used,” the company said.
MobiBurn, on the other hand, stated that it never collected information and that it simply acted as an intermediary between the applications. However, it intends to stop its operations until the investigations into the case are completed.
This incident is another reminder that we must always be careful about the applications we download and not choose those that do not come from trusted developers.
