HomeSecurityTwitter: Android bug exposes DMs and other user data to hackers!

Twitter: Android bug exposes DMs and other user data to hackers!

Twitter announced that it has fixed a bug found in the Twitter for Android app that could have allowed hackers to gain access to Twitter user data, including direct messages (DMs). Specifically, the company said in a related announcement that it recently discovered and fixed a bug in Twitter for Android related to a security issue in the Android operating system affecting OS versions 8 and 9 .

The company added that about 96% of Twitter for Android users already have an Android security patch installed that protects them from this bug. However, for the remaining 4% of users of the app, this bug could allow hackers, through a malicious app installed on their device, to gain access to Twitter user data, such as direct messages (DMs), by using Android system permissions that provide protection against this.

Twitter error

According to the company, there is no evidence yet that hackers have exploited this bug discovered in Twitter for Android. In addition to fixing the security issue in Twitter for Android, to prevent malicious apps from gaining access to user data located within the Twitter app, adding additional security measures beyond standard OS protections, the company is taking the following actions:


• Asking anyone who may be affected to update Twitter for Android.
• Sending in-app notifications to anyone who may be affected to let them know if they need to take any action.
• Making changes to its processes to better protect against security issues.

Twitter error

Additionally, Twitter is urging all Android users to update Twitter for Android to the latest version, which fixes this bug, on all their devices, clarifying that this issue does not affect Twitter for iOS or Twitter.com.

In July, hackers were able to take control of high-profile Twitter accounts after stealing Twitter employee credentials and gaining access to internal admin tools, following a phishing attack that took place on July 15, 2020. The compromised accounts were then used to promote a Bitcoin scam to the high-profile users' fans, with the hackers collecting approximately $120,000 worth of Bitcoin.

After the attack, U.S. Senator Ron Wyden tweeted about a conversation he had with Twitter CEO Jack Dorsey two years ago, when he was told the company was working on end-to-end encrypted DMs. Wyden said that if hackers were able to gain access to users’ DMs, the breach could have a major impact for years to come. In January, the company updated Twitter for Android to fix an issue that caused the app to “crash” when opened.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS