Twitter announced that it has already fixed a vulnerability in the app’s Android version that might have allowed other people taking over a user’s account. Once hijacked, it would have allowed the other party to send direct messages or post tweets using the affected account, the company said in a post.
The vulnerability might have also allowed bad actors to view location information, direct messages and protected tweets as well once an account is hijacked, ZDNet reported. Taking over an account is possible if hackers inserted “malicious code into restricted storage areas of the Twitter app.”
Thankfully, the company said it found no evidence suggesting that someone might have exploited this vulnerability. However, it also admitted that it can’t say for sure that someone hasn’t.
“We don’t have evidence that malicious code was inserted into the app or that this vulnerability was exploited, but we can’t be completely sure so we are taking extra caution,” Twitter said.
Thus Twitter sent notifications to potentially affected users of the app. These notifications also contain specific steps to follow that might vary depending on the app version they are using.
“We have taken steps to fix this issue and are directly notifying people who could have been exposed to this vulnerability either through the Twitter app or by email with specific instructions to keep them safe,” Twitter said. “These instructions vary based on what versions of Android and Twitter for Android people are using.”
Meanwhile, Twitter also announced that it is blocking animated PNG files in tweets. The company said that these files ignore autoplay settings and might pose a threat to people who are sensitive to flashing images, ZDNet reported.
“PNGs ignore our safeguards and can cause performance issues for the app and your device,” Twitter said. “Today we're fixing the bug which will no longer allow APNGs to animate when tweeted.”
The move came after the Epilepsy Foundation filed a complaint after attackers used its handle and hashtags when posting APNGs with flashing and strobing lights. “These attacks are no different than a person carrying a strobe light into a convention of people with epilepsy and seizures, with the intention of inducing seizures and thereby causing significant harm to the participants,” said Allison Nichol, Esq., a director of the foundation.


OpenAI Pulls the Plug on Sora, Ending $1 Billion Disney Partnership
Meta Ties Executive Pay to Aggressive Stock Price Targets in Major Retention Push
Elliott Investment Management Takes Multibillion-Dollar Stake in Synopsys
Nanya Technology Shares Surge 10% After $2.5 Billion Private Placement from Sandisk and Cisco
SK Hynix Eyes Up to $14 Billion U.S. IPO to Fund AI Chip Expansion
TSMC Japan's Second Fab to Produce 3nm Chips by 2028
NVIDIA's Feynman AI Chip May Face Redesign Amid TSMC Capacity Crunch
Meta and Google just lost a landmark social media addiction case. A tech law expert explains the fallout
Microsoft Eyes $7B Texas Energy Deal to Power AI Data Centers
SMIC Allegedly Supplies Chipmaking Tools to Iran's Military, U.S. Officials Warn
Golden Dome Missile Defense: Anduril and Palantir Join Forces on Trump's $185B Space Shield
Palantir's Maven AI Earns Pentagon "Program of Record" Status, Reshaping Military AI Strategy
SpaceX IPO Filing Expected This Week as Valuation Could Surpass $75 Billion
Federal Judge Blocks Pentagon's Blacklisting of AI Company Anthropic
Judge Dismisses Sam Altman Sexual Abuse Lawsuit, But Sister Can Refile
Rubio Directs U.S. Diplomats to Use X and Military Psyops to Counter Foreign Propaganda
NASA's Artemis II Crew Arrives in Florida for Historic Moon Mission 



