Twitter Warns of Account Hijacking Flaw in Android App, Urges Immediate Updates

Anyone running an older version of the Twitter app on Android might want to reconsider their update phobia. Twitter reports that a flaw in the app could have allowed an attacker to access accounts to see protected data and even post content as if they were the victim. The vulnerability is patched in the latest versions, but that won’t matter if you’ve got automatic updates turned off.
Twitter released scant details of the hack in its recent Privacy Center blog post. It only said that the process to break into an account via the Android app was “complicated” and involved injecting malicious code into restricted storage areas of the app. It did not specify whether or not someone needed physical access to the device, but that’s probably dependent on the availability of other exploits. By chaining several attacks together, it may be possible to remotely compromise the Twitter client.
Regardless of how difficult the attack was, taking over Twitter accounts is a high-reward attack. Someone could use this to push malware on large numbers unsuspecting Twitter users by taking over high-profile accounts. Imagine if Elon Musk’s real Twitter account suddenly tweeted a link to free Bitcoins. A lot of people would click of only out of sheer curiosity.

Twitter pushed out a patch for this update in November. Users on Android 5.0 Lollipop or later should now be on v8.18 or later for full protection. Twitter even went to the effort of releasing an update for Android users on the ancient KitKat version of the OS (v7.93.4), also in November. The company waited until now to ensure most users would be updated. Even the vague explanation from the blog post could point online criminals in the direction of the flaw.
Twitter users with third-party clients are not affected by the bug, nor are those on iOS. You can all continue tweeting without hurriedly checking your client version. Android users on the old version of the official Twitter client should update immediately. It is also generally inadvisable to disable automatic updates in the Play Store. You can (and should) turn on automatic updates in the Play Store settings under “Auto-update apps.” You can choose between Wi-Fi only (the defaut), over any network, and not at all.
Continue reading

New Intel Rocket Lake Details: Backwards Compatible, Xe Graphics, Cypress Cove
Intel has released a bit more information about Rocket Lake and its 10nm CPU that's been back-ported to 14nm.

RISC-V Tiptoes Towards Mainstream With SiFive Dev Board, High-Performance CPU
RISC V continues to make inroads across the market, this time with a cheaper and more fully-featured test motherboard.

ARMing for War: New Cortex-A78C Will Challenge x86 in the Laptop Market
ARM took another step towards challenging x86 in its own right with the debut of the Cortex-A78C this week. The new chip packs up to eight "big" CPU cores and up to an 8MB L3 cache.

Google Kills Free Photo Storage, Changes What Counts Toward Storage Caps
Google has announced some significant changes to Photos, especially if you use the service for automatic backup.