Categories: NewsTech

Twitter admits Android app vulnerability that exposed user’s private data

It seems that Twitter can’t catch a break. The social media platform recently disclosed it discovered a vulnerability in its Android app that can be exploited to allow malicious parties to access a user’s private data including their direct messages (DM).

Twitter explained in a post that it recently discovered the existence of the vulnerability in the Android app that could have allowed an attacker, through a malicious app installed on the device, to access private Twitter data by working around Android’s system permissions. The issue is apparently not new as it is related to a problem that Google had already fixed in its October 2018 security patch.

Here are the steps recommended by Twitter:

1. Updated Twitter for Android to make sure external apps can’t access Twitter in-app data by adding extra safety precautions beyond standard OS protections

2. Requiring anyone that may be impacted to update Twitter for Android

3. Sending in-app notices to everyone who could have been vulnerable to let them know if they need to do anything

4. Identifying changes to our processes to better guard against issues like this

The good news is that 96% of Twitter users on Android are not vulnerable to this issue. But that also means the remaining 4% of users on Android 8 and Android 9 were exposed to this exploit. Twitter, however, said there was no evidence the vulnerability was exploited.

This isn’t the first vulnerability Twitter has detected in its Android app. The company has previously disclosed a similar problem after a fix was made available. 

In mid-July 2020, Twitter suffered an unprecedented hack that compromised the accounts of high-profile individuals such as Bill Gates, Elon Musk and Joe Biden.

The mastermind behind the hack was revealed to be Graham Ivan Clark, a 17-year-old teenager from Florida, who was arrested on 31 July. Based on The New York Times’ story, Clark tricked an unwitting employee via a phone phishing attack and gained access to Twitter’s account management tools.

[SOURCE]

Related reading

Recent Posts

First-ever BMW iX4: Coupe-style electric SUV with 828km range and 400kW DC charging

BMW has officially unveiled the first-ever BMW iX4, a fully electric SUV coupe that serves…

9 minutes ago

Realme 10.10 sale: Discounts up to 50% off, phone promos from RM549 and more

If you are planning to upgrade your smartphone, Realme is kicking off its 10.10 Double…

2 hours ago

Samsung 10.10 Syok Deals: Get up to 40% off for Galaxy S25 Ultra, Galaxy Tab S10 FE+ and more starting 9 October

Samsung Malaysia is rolling out its annual 10.10 Syok Deals promotion, cutting prices by up…

2 hours ago

OpenAI rolls out GPT-6 and Intelligent UI: Here is what you need to know

OpenAI has rolled out Intelligent UI to 1.2 billion weekly ChatGPT users. The feature replaces…

2 hours ago

Proton X50 Sport Edition 2026 officially revealed: Blacked-out look, red accents, now open for booking

After it was first previewed at the Kuala Lumpur International Mobility Show (KLIMS) 2026 back…

5 hours ago

Rapid Bus trials new EV buses with Rapid KL and Rapid Penang

Prasarana Malaysia’s subsidiary, Rapid Bus, has begun testing electric buses across its Rapid KL and…

21 hours ago

This website uses cookies.