Skip to main content

Update your Twitter app right now if you’re on Android

Twitter says it has patched a vulnerability inside its Android app that could have potentially let malicious actors view information of private accounts and take over profiles through an intricate back-end process. If a hacker managed to exploit the loophole, they could send direct messages and tweets on the target account’s behalf.

The social network claims so far it hasn’t discovered any affected user, nor found evidence of whether a third-party service has taken advantage of the bug. However, Twitter is reaching out to the people whose details may have been exposed. It’s unclear how long the vulnerability was left out in the open. The issue is not present on Twitter’s iOS app.

Twitter is now rolling out an update to its Android app. So if you’re an Android user, you should head over to the Play Store and install it immediately irrespective of whether Twitter contacted you.

“We don’t have evidence that malicious code was inserted into the app or that this vulnerability was exploited, but we can’t be completely sure so we are taking extra caution. We have taken steps to fix this issue and are directly notifying people who could have been exposed to this vulnerability either through the Twitter app or by email with specific instructions to keep them safe,” the company said in a blog post.

Since the method for abusing the glitch wasn’t all that straightforward, it’s unlikely a lot of users have been impacted due to this. Twitter essentially left a sensitive storage area of its app unprotected. By either through another third-party app or an unverified online download, a hacker could, in theory, exploit that to insert a piece of malicious code into where Twitter stores your private information on your phone and misused that access to fetch your personal data as well as post messages and tweets from your profile.

This latest security flaw is, in a lot of ways, similar to the one that happened about a month ago. On November 25, Facebook and Twitter said private data of “hundreds of their users” was compromised through malicious third-party Android apps. The breach, the two social media companies claimed, was caused because there wasn’t sufficient isolation between various software developer kits within a single app on Android.

Editors' Recommendations

Shubham Agarwal
Shubham Agarwal is a freelance technology journalist from Ahmedabad, India. His work has previously appeared in Firstpost…
The Google app on your Android phone is getting a helpful new feature
Google app on Android beta showing Notifications.

The Google app for Android phones is getting a helpful new feature to make search even better. The latest beta has a dedicated "Notifications" feed in its bottom bar. The feature was first introduced on the mobile version of Google for Android earlier this year. The app feature was first noticed by 9to5Google.

The app now includes a Notifications option at the bottom, next to Discover, Search, and Saved items. The Notifications section displays a continuous list of alerts from Google Search, weather conditions, flight information, sports scores, movies and TV shows, and more. The notifications are grouped under “Today” and “Earlier." This feature should prove handy if you miss a notification from the Google app, as it provides a more focused view than Android's system-level history.

Read more
Android 15 release date: When will my phone get the update?
The Android 15 logo on a smartphone.

Google has announced and shown off Android 15, which is the next major version of its mobile operating system. The development and release cycle of Android typically has a three-phase strategy, and that applies to Android 15 as well.

The first phase is always the Developer Preview phase, which happened earlier this year. It’s then followed by the more public Beta testing phase, and then the final, stable version comes out for everyone.

Read more
Google has a magical new way for you to control your Android phone
Holding the Google Pixel 8 Pro, showing its Home Screen.

You don’t need your hands to control your Android phone anymore. At Google I/O 2024, Google announced Project Gameface for Android, an incredible new accessibility feature that will let users control their devices with head movements and facial gestures.

There are 52 unique facial gestures supported. These include raising your eyebrow, opening your mouth, glancing in a certain direction, looking up, smiling, and more. Each gesture can be mapped to an action like pulling down the notification shade, going back to the previous app, opening the app drawer, or going back to home. Users can customize facial expressions, gesture sizes, cursor speed, and more.

Read more