Executive brief
The Twilio Authy API contained an unauthenticated endpoint that allowed attackers to verify if specific phone numbers were registered with the service. By submitting a stream of phone numbers, unauthorized actors could perform large-scale information disclosure, though Twilio stated that Authy accounts themselves were not compromised.
Affected products
- Twilio Authy Android before 25.1.0
- Twilio Authy iOS before 26.1.0
Timeline
- 2024-06: exploited: Exploited in the wild.
- 2024-07-02: disclosed
- 2024-07-23: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2024-07-23: advisory