Skip to main content

Eavesdropper: The Mobile Vulnerability Exposing Business Apps

A vulnerability has been found in the Twilio SDK and Rest API that provides standardised voice and text communication capabilities to mobile applications.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

A vulnerability has been found in the Twilio SDK and Rest API that provides standardised voice and text communication capabilities to mobile applications.

Affected platforms

The following platforms are known to be affected:

Threat details

It allows any user to steal the metadata associated with these communications. This vulnerability is notable for the ease with which an attacker can steal data. Once a vulnerable app is found, there is minimal effort needed and it can be exploited remotely.

By hardcoding plaintext Twilio default credentials into their apps, 85 separate developers have exposed at least 685 apps (56% iOS, 44% Android) to this vulnerability, 33% of which are enterprise-focused. As of August 2017, 102 were available on the iOS and 75 on Google Play, with the Android apps being downloaded 180 million times.

Exploitation of the vulnerability is as simple as acquiring the default credentials (e.g. by downloading the SDK) and finding an application that uses hardcoded credentials. By using a tool such as YARA, an attacker can pull the Twilio account details and phone number associated with them; before using these to access the Twilio API where they can steal metadata, including messaging and voice files.


Remediation steps

Type Step
  • Organisations should cease to use mobile applications that employ the Twilio API where possible, or should ascertain that these apps do not use default credentials.
  • Employees should only use approved applications for business-related communications.

Last edited: 17 February 2020 11:30 am