Twitter seals leak that could allow attacker access to DMs

Spread the love

Twitter has leaked a poem that could have allowed an attacker to access DMs on an Android phone. The vulnerability was only exploitable on 4 percent of Android phones, because 96 percent of users already had a fix through a security update.

Twitter does not state exactly what kind of vulnerability it is, but says it is related to a leak in Android 8 and 9 that was fixed in October 2018. About 96 percent of users have a security update that already made the exploit impossible.

The attack required a separate malicious app on the device to access sensitive data in the Twitter app. It is believed to be CVE-2018-9492, a leak in ActivityManagerService.java to access data from other apps. According to Twitter, the leak has not been exploited. The app has been updated to make the attack permanently impossible. The attack was impossible on iOS and in the web version of Twitter.

You might also like