CVE-2024-39891

In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-number data, as exploited in the wild in June 2024. Specifically, the endpoint accepted a stream of requests containing phone numbers, and responded with information about whether each phone number was registered with Authy. (Authy accounts were not compromised, however.)
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:twilio:authy:*:*:*:*:*:iphone_os:*:*
cpe:2.3:a:twilio:authy_authenticator:*:*:*:*:*:android:*:*

History

24 Jul 2024, 14:38

Type Values Removed Values Added
CPE cpe:2.3:a:twilio:authy:*:*:*:*:*:iphone_os:*:*
cpe:2.3:a:twilio:authy_authenticator:*:*:*:*:*:android:*:*
First Time Twilio
Twilio authy
Twilio authy Authenticator
References () https://cwe.mitre.org/data/definitions/203.html - () https://cwe.mitre.org/data/definitions/203.html - Technical Description
References () https://www.bleepingcomputer.com/news/security/hackers-abused-api-to-verify-millions-of-authy-mfa-phone-numbers/ - () https://www.bleepingcomputer.com/news/security/hackers-abused-api-to-verify-millions-of-authy-mfa-phone-numbers/ - Press/Media Coverage
References () https://www.twilio.com/docs/usage/security/reporting-vulnerabilities - () https://www.twilio.com/docs/usage/security/reporting-vulnerabilities - Product
References () https://www.twilio.com/en-us/changelog - () https://www.twilio.com/en-us/changelog - Product, Release Notes

03 Jul 2024, 22:15

Type Values Removed Values Added
References
  • () https://www.bleepingcomputer.com/news/security/hackers-abused-api-to-verify-millions-of-authy-mfa-phone-numbers/ -
Summary (en) In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-number data. (Authy accounts were not compromised, however.) (en) In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-number data, as exploited in the wild in June 2024. Specifically, the endpoint accepted a stream of requests containing phone numbers, and responded with information about whether each phone number was registered with Authy. (Authy accounts were not compromised, however.)

03 Jul 2024, 12:53

Type Values Removed Values Added
Summary
  • (es) En la API de Twilio Authy, a la que accedía Authy Android antes de 25.1.0 y Authy iOS antes de 26.1.0, un endpoint no autenticado proporcionaba acceso a ciertos datos de números de teléfono. (Sin embargo, las cuentas de Authy no se vieron comprometidas).

03 Jul 2024, 02:05

Type Values Removed Values Added
CWE CWE-203

02 Jul 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-02 18:15

Updated : 2024-07-24 14:38


NVD link : CVE-2024-39891

Mitre link : CVE-2024-39891

CVE.ORG link : CVE-2024-39891


JSON object : View

Products Affected

twilio

  • authy_authenticator
  • authy
CWE
CWE-203

Observable Discrepancy