Skip to main content

Malicious SDK may have stolen personal data of Facebook, Twitter users

It seems like there has been yet another data leak. Both Facebook and Twitter have announced that the personal data of multiple users, who use their social media accounts to log into certain apps that were downloaded from the Google Play Store. 

In its official statement, Twitter noted that the vulnerability was not is Twitter’s software, but rather a lack of isolation between SDKs within an application. The micro-blogging site claims that the SDK maintained by oneAudience could be embedded within a mobile application, and could exploit a vulnerability in the mobile ecosystem. This could include access to personal information such as email, username, and last Tweet. Twitter also notes that while it could not find any evidence that the SDK was used to take over an account, it is possible to do so. However, it did find evidence that it was used to access personal data of some Twitter users on Android, but notes that there is no evidence that the iOS version of the SDK targeted people who use Twitter for iOS. Twitter also says that it informed both Google and Apple about the malicious SDK, so they those companies can also take the necessary action.

In a statement to CNBC, a Facebook spokesperson noted that there besides Oneaudience, Mobiburn was also developing malicious SDKs. Following its own investigation, Facebook claims that the apps have been removed from the platform and it has issued cease and desist letters against Oneaudience and Mobiburn. 

Both Facebook and Twitter plan to personally notify users affected by the issue. Twitter advises users to check which third-party apps users have authorised to their account and remove any that they do not recognise or no longer use. Facebook advises users to be more careful when selecting third-party apps to grant access to.



from Latest Technology News https://ift.tt/37AaYUR

Comments

Popular posts from this blog

What if a botched Google search card says you are a serial killer

Many of us have come to heavily rely on Google Search and often don’t question the veracity of information Google cherry-picks from the vast data available on the world wide web for its search cards. This incident, which is one part funny and two parts scary, makes it clear that Google’s Knowlege Graph may not be as sacrosanct as you may have believed.  Hristo Georgiev was informed by a former colleague that a Google search of his name returned a Google Knowlege Graph that depicted his photo and linked it to a Bulgarian rapist and serial killer of the same name, also known as ‘The Sadist’, who murdered five people back in the 1970s and was later executed by shooting.  The graph linked the info to a Wikipedia article, which incidentally had no link to any of Georgiev’s profile or his image. It was Google’s algorithms that erroneously matched the two. What’s even more problematic is that Hristo Georgiev is not a unique name and is shared by hundreds of other people.  As...

MWC 2023: A comparison of the top 4 Xiaomi 13 vs Xiaomi 13 Pro features

Xiaomi launched the Xiaomi 13 and Xiaomi 13 Pro globally a day before MWC 2023. And if you are planning to buy a new Xiaomi flagship phone, you may need clarity on the Xiaomi 13 and Xiaomi 13 Pro differences. The latter is the bigger, better, and pricier model of the two.  So, what we will be doing here is comparing the specs, features and price of these two phones and finding out which one better fits your bill. Xiaomi 13 vs Xiaomi 13 Pro comparison These differences between Xiaomi 13 and Xiaomi 13 Pro might affect your buying decision. We will be comparing the two Xiaomi phones based on their design, display, performance factors, battery, camera, and price. 1. Design Xiaomi 13 Pro is slightly thicker and heavier than Xiaomi 13. It comes with Gorilla Glass Victus protection on the front and a ceramic back option. 2. Display Xiaomi 13 Pro has got a curvy-edged display whilst the regular 13 has a flat front panel. The Pro model has an LTPO screen which means an adaptive refres...