Twitter issues emergency security patch for Android

Android users told to update app after discovery of serious vulnerability

If you use Twitter for Android, pick up your phone and update the app – the company has just issued a patch for a particularly dangerous flaw.

Twitter admitted in a blog post that it had spotted a nasty vulnerability that could let hackers see private account information or take over your feed to send Tweets or Direct messages. A patch is already being pushed out, and there's no evidence the flaw had been spotted or used in the wild.

Twitter said that making use of the flaw would have involved a "complicated process" that required inserting malicious code into restricted storage areas of the app, but admitted it may have been possible.

"We don’t have evidence that malicious code was inserted into the app or that this vulnerability was exploited, but we can’t be completely sure so we are taking extra caution," the company said.

Alongside patching the flaw, the company said it would directly contact anyone exposed to the flaw, either via the app or by email, with instructions on how to keep their accounts safe. "We recommend that people follow these instructions as soon as possible," the company said. "If you are unsure about what to do, update to the latest version of Twitter for Android."

The app can be updated via the Play Store on Android. Twitter said the iOS version of the app was not affected by the flaw.

For anyone wanting more information, Twitter has a form to request information about your account and security. "We’re sorry this happened and will keep working to keep your information secure on Twitter," the post added.

The security flaw comes as the company purged 88,000 accounts that were used as part of a "significant state-backed information operation on Twitter originating in Saudi Arabia". The spam accounts were spreading pro-Saudi propaganda via a variety of platform manipulation techniques, such as aggressive liking, Twitter said. The campaign was coordinated by a Saudi marketing company, Smaat, which has been banned permanently from Twitter.

Featured Resources

2021 Thales cloud security study

The challenges of cloud data protection and access management in a hybrid and multi cloud world

Free download

IDC agility assessment

The competitive advantage in adaptability

Free Download

Digital transformation insights from CIOs for CIOs

Transformation pilotes, co-pilots, and engineers

Free download

What ITDMs did next - and what they should be doing now

Enable continued collaboration and communication for hybrid workers

Most Popular

What should you really be asking about your remote access software?
Sponsored

What should you really be asking about your remote access software?

17 Nov 2021
What are the pros and cons of AI?
machine learning

What are the pros and cons of AI?

30 Nov 2021
Meta picks AWS to help expand its AI services
cloud computing

Meta picks AWS to help expand its AI services

2 Dec 2021