Junglewise Threat Intelligence

CVE-2024-39891: Twilio Authy Information Disclosure Vulnerability

CVE-2024-39891 · Severity: critical · CVSS 5.3 · Exploited in the wild · Published 2024-07-23

Executive brief

The Twilio Authy API contained an unauthenticated endpoint that allowed attackers to verify if specific phone numbers were registered with the service. By submitting a stream of phone numbers, unauthorized actors could perform large-scale information disclosure, though Twilio stated that Authy accounts themselves were not compromised.

Affected products

  • Twilio Authy Android before 25.1.0
  • Twilio Authy iOS before 26.1.0

Timeline

  • 2024-06: exploited: Exploited in the wild.
  • 2024-07-02: disclosed
  • 2024-07-23: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2024-07-23: advisory