Twitter Warns of Account Hijacking Flaw in Android App, Urges Immediate Updates

Twitter Warns of Account Hijacking Flaw in Android App, Urges Immediate Updates

Anyone running an older version of the Twitter app on Android might want to reconsider their update phobia. Twitter reports that a flaw in the app could have allowed an attacker to access accounts to see protected data and even post content as if they were the victim. The vulnerability is patched in the latest versions, but that won’t matter if you’ve got automatic updates turned off.

Twitter released scant details of the hack in its recent Privacy Center blog post. It only said that the process to break into an account via the Android app was “complicated” and involved injecting malicious code into restricted storage areas of the app. It did not specify whether or not someone needed physical access to the device, but that’s probably dependent on the availability of other exploits. By chaining several attacks together, it may be possible to remotely compromise the Twitter client.

Regardless of how difficult the attack was, taking over Twitter accounts is a high-reward attack. Someone could use this to push malware on large numbers unsuspecting Twitter users by taking over high-profile accounts. Imagine if Elon Musk’s real Twitter account suddenly tweeted a link to free Bitcoins. A lot of people would click of only out of sheer curiosity.

Twitter Warns of Account Hijacking Flaw in Android App, Urges Immediate Updates

Twitter pushed out a patch for this update in November. Users on Android 5.0 Lollipop or later should now be on v8.18 or later for full protection. Twitter even went to the effort of releasing an update for Android users on the ancient KitKat version of the OS (v7.93.4), also in November. The company waited until now to ensure most users would be updated. Even the vague explanation from the blog post could point online criminals in the direction of the flaw.

Twitter users with third-party clients are not affected by the bug, nor are those on iOS. You can all continue tweeting without hurriedly checking your client version. Android users on the old version of the official Twitter client should update immediately. It is also generally inadvisable to disable automatic updates in the Play Store. You can (and should) turn on automatic updates in the Play Store settings under “Auto-update apps.” You can choose between Wi-Fi only (the defaut), over any network, and not at all.

Continue reading

Great, Now Games Are Hijacking Systems With Cryptocurrency Miners
Great, Now Games Are Hijacking Systems With Cryptocurrency Miners

We've graduated from browser-based cryptojacking to crypto-hijackers that embed their work in games. Hurray.

Fortnite Left Players Open to Account Hijacking, Voice Chat Eavesdropping
Fortnite Left Players Open to Account Hijacking, Voice Chat Eavesdropping

Security firm Check Point Software says Fortnite developer Epic Games had a major vulnerability in its system that could have allowed an attacker to play as the victim, purchase items, and even listen to the player's microphone.

Samsung, Pixel Users No Longer at Risk for Android Camera App Hijacking
Samsung, Pixel Users No Longer at Risk for Android Camera App Hijacking

The companies didn't know about the bug until earlier this year when researchers from Checkmarx alerted them. It's a good thing, too. This could have been a huge mess if someone exploited it in the wild.