Twitter and Facebook have confirmed millions of users may have had their personal information compromised by malicious software hidden in third-party apps. This includes names, genders, emails, usernames, and potentially people's last tweets.
"We recently received a report about a malicious mobile software development kit (SDK) maintained by oneAudience," Twitter announced in a blog post on Monday. Concealed in apps downloaded from the Google Play Store, the SDK could "exploit a vulnerability in the mobile ecosystem" to expose users' personal data to third-party developers.
Apps often ask for access to users' social media, linking to Twitter and Facebook accounts to provide features such as in-game leaderboards and the ability to share achievements. However, doing so in an app using this SDK potentially allowed third-party developers to access much more data than users had agreed to.
"While we have no evidence to suggest that this was used to take control of a Twitter account, it is possible that a person could do so," wrote Twitter.
Fortunately, there is nothing to suggest iOS users were impacted. Unfortunately, the vulnerability was exploited to access the data of some Twitter users on Android.
Twitter says it has informed Google and Apple of the issue, and will be notifying those who may have been impacted. However, there isn't much people can do other than delete unused apps, clean up their app permissions, and hope they weren't affected.
SEE ALSO: Facebook wants to pay you for your opinions. What could go wrong?Facebook users were similarly affected by the oneAudience SDK, as well as a similar SDK from MobiBurn. "[Both] were paying developers to use malicious software developer kits (SDKs) in a number of apps available in popular app stores," said Facebook.
The company will also notify potentially affected users, who number a whopping 9.5 million. In a statement to CNBC, Facebook claimed it has since removed the offending apps, as well as issued a cease and desist to both oneAudience and MobiBurn.
In response, oneAudience released a statement on Monday saying it will be shutting down its SDK immediately, though noted it had already pushed an update to prevent such data collection once informed of the vulnerability. "This data was never intended to be collected, never added to our database and never used," said oneAudience.
MobiBurn also released a statement asserting it had not "collected, shared or monetised" any data from Facebook, and characterised itself as a mere middleman who introduces app developers to third-party data monetisation companies.
Even so, MobiBurn will cease all activities until it completes its investigation into the matter.
All of this is another reminder to be mindful of what you download, and never link apps to your social media accounts if you can avoid it. Your friends probably don't care about your high score anyway.
Copyright © 2023 Powered by
Millions of Twitter and Facebook users may have had their personal information compromised-燕尔新婚网
sitemap
文章
1
浏览
21
获赞
4873
Please take a moment to appreciate Bernie Sanders dancing to ABBA
Bernie Sanders spent the weekend dancing. The Democratic presidential candidate attended a "Labor SoThe Museum of Selfies is here to clog your News Feed
Your sister's friend's duckface selfie might not compare to the Mona Lisa on first glance (or at allStar Wars Holiday Gift Guide: Your shopping mission starts here
Soon, we’ll all get to spend 192 minutes watching battle scenes a galaxy far, far away. But foNissan's freaky AR concept would project friends in your car, make it look sunny outside
Nissan calls it Invisible-to-Visible, or I2V technology, but you can call it creepy. The company wanTwitter and Facebook restrict sharing of disputed 'NY Post' article ahead of election
Facebook and Twitter restricted the spread of a disputed New York Postarticle on Wednesday.The articQueen of Christmas Mariah Carey has issued her order on when to take down the tree
Alas, Christmas is all but done and dusted. But, Mariah Carey isn't anywhere near ready to bid farewApple is building a $1 billion campus in Austin
Apple is planning a major expansion of its operations across the U.S., including a $1 billion investStarbucks Christmas Tree Frappuccino tastes like sugar and regret (but I took many photos)
Nothing says Christmas like a cold cup of sugar. At least that's what I kept telling myself as I tooFacebook engineer quits, says company is 'profiting off hate'
A Facebook engineer has published a scathing resignation letter accusing the company of "profiting oYou can now give your Google Assistant a British or Australian accent
Now you can get your Google Assistant device to say "g'day."The voice assistant features two new voiMystery crocodile turns up at house on Christmas, many people claim it
Here's an absolute croc of a story.A one-metre-long freshwater crocodile was found "sitting quietly"Super Micro report: No, there was no secret Chinese hardware implant
Super Micro has not moved on.The San Jose-based motherboard manufacturer found itself mired in contr21 Years of Hitman: How Stealth Action Got Perfected Over the Last 2 Decades
Coming off the highly anticipated release of Hitman 3, this latest installment has been very well reHacker uses internet meme to send hidden commands to malware
A recently discovered piece of malware has a unique way of communicating with its creator—throPut off laundry day even longer with LG's self
Laundry day sucks. And while we don't yet have robots that can actually do our laundry for us (well,