Twitter issues emergency security patch for Android
Android users told to update app after discovery of serious vulnerability
If you use Twitter for Android, pick up your phone and update the app – the company has just issued a patch for a particularly dangerous flaw.
Twitter admitted in a blog post that it had spotted a nasty vulnerability that could let hackers see private account information or take over your feed to send Tweets or Direct messages. A patch is already being pushed out, and there's no evidence the flaw had been spotted or used in the wild.
Twitter said that making use of the flaw would have involved a "complicated process" that required inserting malicious code into restricted storage areas of the app, but admitted it may have been possible.
"We don’t have evidence that malicious code was inserted into the app or that this vulnerability was exploited, but we can’t be completely sure so we are taking extra caution," the company said.
Alongside patching the flaw, the company said it would directly contact anyone exposed to the flaw, either via the app or by email, with instructions on how to keep their accounts safe. "We recommend that people follow these instructions as soon as possible," the company said. "If you are unsure about what to do, update to the latest version of Twitter for Android."
The app can be updated via the Play Store on Android. Twitter said the iOS version of the app was not affected by the flaw.
For anyone wanting more information, Twitter has a form to request information about your account and security. "We’re sorry this happened and will keep working to keep your information secure on Twitter," the post added.
The security flaw comes as the company purged 88,000 accounts that were used as part of a "significant state-backed information operation on Twitter originating in Saudi Arabia". The spam accounts were spreading pro-Saudi propaganda via a variety of platform manipulation techniques, such as aggressive liking, Twitter said. The campaign was coordinated by a Saudi marketing company, Smaat, which has been banned permanently from Twitter.
Unleashing the power of AI initiatives with the right infrastructure
What key infrastructure requirements are needed to implement AI effectively?Download now
Achieve today. Plan tomorrow. Making the hybrid multi-cloud journey
A Veritas webinar on implementing a hybrid multi-cloud strategyDownload now
A buyer’s guide for cloud-based phone solutions
Finding the right phone system for your modern businessDownload now
The workers' experience report
How technology can spark motivation, enhance productivity and strengthen securityDownload now