Twitter reveals security flaw that may have left your DMs vulnerable

twitter-logo-oneplus-6.jpg

The company couldn’t find any evidence that hackers had used the vulnerability.

What you need to know

  • Twitter today disclosed a vulnerability in its Android app.
  • The security flaw could have allowed attackers to access a user’s private information, including their DMs.
  • The company claims only about 4% of its userbase on Android is vulnerable.

A vulnerability in Twitter’s Android app, based on an underlying flaw in Android itself that was disclosed back in 2018, could have allowed malicious actors to access a user’s personal information, Twitter reported today.

The issue only affected users on Android 8 and 9, and by Twitter’s estimates, 96% of its user base on Android already have the relevant security patches installed on their device that safeguard them from this exploit. To protect the remaining 4% of users — which the company calls a ‘small group’, despite having a billion downloads on the Play Store — Twitter announced that it’s doing the following:

Updated Twitter for Android to make sure external apps can’t access Twitter in-app data by adding extra safety precautions beyond standard OS protections
Requiring anyone that may be impacted to update Twitter for Android
Sending in-app notices to everyone who could have been vulnerable to let them know if they need to do anything
Identifying changes to our processes to better guard against issues like this

The company noted that it found no evidence that hackers had used this particular vulnerability, but still urged everyone to update the app.

The news comes just weeks after a major bitcoin scam involving the Twitter accounts of several high-profile people, such as Bill Gates, Elon Musk, Barack Obama, and others. The incident has already resulted in the arrests of three individuals: a 19-year-old from the U.K. and two individuals from Florida, one of whom is a minor.

How to make your Instagram, Twitter, TikTok, and other social media accounts private

Related posts

Latest posts

Apple Says iPhone Driver’s Licenses Coming to These 8 U.S. States, But Rollout Remains Slow

In select U.S. states, residents can add their driver's license or state ID to the Wallet app on the iPhone

Get $100 Off iPad Mini 7 on Amazon, Available From $399

Amazon this week is providing record low prices on multiple models of the iPad mini 7, starting at $399.00 for

Apple Says New EU Interoperability Rules ‘Bad for Our Products and Our Users’

The European Commission today announced the decisions of its interoperability proceedings to assist Apple in complying with its obligations under

Google’s New $499 Pixel 9a Tops the iPhone 16e in Four Ways

Google today introduced the Pixel 9a, its latest lower-priced smartphone. The device is launching in April, and it will compete

Apple Studio Display Gets Massive $350 Discount on Amazon

Amazon has introduced a new all-time low price on the Apple Studio Display, available for $1,249.00, down from $1,599.00. This

Here’s How the iPhone 16e’s C1 Modem Stacks Up Against the iPhone 16 Qualcomm Modem

The iPhone 16e includes Apple's first custom-designed C1 modem, and since it's a new chip category for Apple, there have

iOS 19 and iOS 20 Must Include a Long List of Major Changes, EU Says

The European Commission today announced a long list of changes that Apple is legally required to implement in future iOS

Getting a Google Play services error? You’re not the only one

A Google Play Store bug is prompting users to download an update when there isn't one to be found, but thankfuly, the bug seems mostly harmless.

I wore the OnePlus Watch 3 and Galaxy Watch 7. Here’s the one to buy

I've spent weeks with both the OnePlus Watch 3 and the Samsung Galaxy Watch 7. Both are excellent smartwatches, but one is the better buy.

WhatsApp makes move to cut the number of spam messages you get

WhatsApp is setting limits on broadcast messages sent by individual and business accounts.