Skip to main content

Update your Twitter app right now if you’re on Android

Twitter says it has patched a vulnerability inside its Android app that could have potentially let malicious actors view information of private accounts and take over profiles through an intricate back-end process. If a hacker managed to exploit the loophole, they could send direct messages and tweets on the target account’s behalf.

The social network claims so far it hasn’t discovered any affected user, nor found evidence of whether a third-party service has taken advantage of the bug. However, Twitter is reaching out to the people whose details may have been exposed. It’s unclear how long the vulnerability was left out in the open. The issue is not present on Twitter’s iOS app.

Twitter is now rolling out an update to its Android app. So if you’re an Android user, you should head over to the Play Store and install it immediately irrespective of whether Twitter contacted you.

“We don’t have evidence that malicious code was inserted into the app or that this vulnerability was exploited, but we can’t be completely sure so we are taking extra caution. We have taken steps to fix this issue and are directly notifying people who could have been exposed to this vulnerability either through the Twitter app or by email with specific instructions to keep them safe,” the company said in a blog post.

Since the method for abusing the glitch wasn’t all that straightforward, it’s unlikely a lot of users have been impacted due to this. Twitter essentially left a sensitive storage area of its app unprotected. By either through another third-party app or an unverified online download, a hacker could, in theory, exploit that to insert a piece of malicious code into where Twitter stores your private information on your phone and misused that access to fetch your personal data as well as post messages and tweets from your profile.

This latest security flaw is, in a lot of ways, similar to the one that happened about a month ago. On November 25, Facebook and Twitter said private data of “hundreds of their users” was compromised through malicious third-party Android apps. The breach, the two social media companies claimed, was caused because there wasn’t sufficient isolation between various software developer kits within a single app on Android.

Editors' Recommendations

Shubham Agarwal
Shubham Agarwal is a freelance technology journalist from Ahmedabad, India. His work has previously appeared in Firstpost…
Have one of these Google Pixel phones? You’re getting Circle to Search
Someone holding the Google Pixel 6 Pro and Pixel 6a next to each other.

Circle to Search — Google's excellent search tool that debuted on the Samsung Galaxy S24 earlier this year — is about to become available to more people. Specifically, it's coming to a bunch more Pixel devices, giving even more people a chance to use it for themselves.

As the name implies, Circle to Search allows you to circle or scribble anything on your screen to perform a Google Search for it. It's great for those times you see something on your phone and want to know more about it, but aren't sure how to type out a Google Search for it. It launched on the Galaxy S24, S24 Plus, and S24 Ultra in January and then quickly made its way to the Google Pixel 8 and Pixel 8 Pro.

Read more
Android 15 has two hidden features you’re going to love
The Android 15 logo on a smartphone.

Android 15 is this year's big Android update, and based on what we've seen so far, it's going to be pretty tame. Just like Android 14, Android 15 isn't trying to overhaul or reimagine Android. Instead, it's all about fine-tuning things.

However, that doesn't mean there's nothing cool going on. I've been playing with the Android 15 developer preview for a little while now, and in doing so, I've stumbled across two underrated features that I think a lot of people are going to love.
Notification cooldown is a lifesaver

Read more
Your iPhone just got a new iOS update, and you should download it right now
iPhone 15 Pro display with iPhone 15 Pro Max in background.

Apple has just released a new security update, iOS 17.4.1. This comes a little over two weeks after iOS 17.4, which was a big update. iOS 17.4.1 doesn't add any new features, but it's still an important update you'll want to download as soon as you can.

With iOS 17.4.1, Apple states that the update “provides important bug fixes and security updates and is recommended for all users.” Apple doesn’t mention any specifics of these bug fixes, but more details on what this security update addresses may be revealed at a later date.

Read more