Skip to main content

Update your Twitter app right now if you’re on Android

Twitter says it has patched a vulnerability inside its Android app that could have potentially let malicious actors view information of private accounts and take over profiles through an intricate back-end process. If a hacker managed to exploit the loophole, they could send direct messages and tweets on the target account’s behalf.

The social network claims so far it hasn’t discovered any affected user, nor found evidence of whether a third-party service has taken advantage of the bug. However, Twitter is reaching out to the people whose details may have been exposed. It’s unclear how long the vulnerability was left out in the open. The issue is not present on Twitter’s iOS app.

Twitter is now rolling out an update to its Android app. So if you’re an Android user, you should head over to the Play Store and install it immediately irrespective of whether Twitter contacted you.

“We don’t have evidence that malicious code was inserted into the app or that this vulnerability was exploited, but we can’t be completely sure so we are taking extra caution. We have taken steps to fix this issue and are directly notifying people who could have been exposed to this vulnerability either through the Twitter app or by email with specific instructions to keep them safe,” the company said in a blog post.

Since the method for abusing the glitch wasn’t all that straightforward, it’s unlikely a lot of users have been impacted due to this. Twitter essentially left a sensitive storage area of its app unprotected. By either through another third-party app or an unverified online download, a hacker could, in theory, exploit that to insert a piece of malicious code into where Twitter stores your private information on your phone and misused that access to fetch your personal data as well as post messages and tweets from your profile.

This latest security flaw is, in a lot of ways, similar to the one that happened about a month ago. On November 25, Facebook and Twitter said private data of “hundreds of their users” was compromised through malicious third-party Android apps. The breach, the two social media companies claimed, was caused because there wasn’t sufficient isolation between various software developer kits within a single app on Android.

Shubham Agarwal
Shubham Agarwal is a freelance technology journalist from Ahmedabad, India. His work has previously appeared in Firstpost…
This new Android feature isn’t coming to your Samsung phone after all
Someone holding the Samsung Galaxy S24 Plus.

A screenshot of the Instant Hotspot feature Google

Google has announced seven new features rolling out to Android phones soon, including message editing in Google messages, improved cross-device services, and perhaps most notably Instant Hotspot. This feature streamlines hotspot creation and tethering between your Android phone and tablet or Chromebook, letting you create hotspots without having to deal with passwords and QR codes.

Read more
Does a job listing mean Apple TV is getting an Android phone app?
The Apple TV app listing in Google Play.

There already is an Android app for Apple TV. More than one, actually. Phil Nickinson / Digital Trends

Let's read way too much into a job listing from Apple. Spurred by a (paywalled) piece from Bloomberg under the headline "Apple Signals That It’s Working on TV+ App for Android Phones," the reblogging industry is all atwitter over the idea that an Apple TV app may be coming to Android phones and tablets. And it might!

Read more
The Spotify Android app just got an odd design change
A close-up of the Spotify app icon.

There's a good chance you use Spotify for your music streaming and podcast listening. There's also a good chance you use the Spotify app on your Android phone. If so, you'll soon notice that the app looks a bit different than usual.

How so? The app icon no longer has its distinctive black background. Gasp.

Read more