Skip to main content
CISA Known Exploited Vulnerabilities

Twilio Authy Information Disclosure Vulnerability is confirmed as actively exploited and is listed in the CISA KEV catalog.

Added to KEV
2024-07-23
Remediation due
2024-08-13

Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CISA notes
https://www.twilio.com/en-us/changelog/Security_Alert_Authy_App_Android_iOS; https://nvd.nist.gov/vuln/detail/CVE-2024-39891

Description

In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-number data, as exploited in the wild in June 2024. Specifically, the endpoint accepted a stream of requests containing phone numbers, and responded with information about whether each phone number was registered with Authy. (Authy accounts were not compromised, however.)

Severity

CVSS 3.1 · CNA5.3 MEDIUM
CVSS:3.1/AC:L/AV:N/A:N/C:L/I:N/PR:N/S:U/UI:N
SSVC · CISA-ADP
Exploitationactive
Automatableyes
Technical impactpartial

Affected Products

VendorProductAffected versions
--
n/a

CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.