Eavesdropper: The Mobile Vulnerability Exposing Business Apps
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
By hardcoding plaintext Twilio default credentials into their apps, 85 separate developers have exposed at least 685 apps (56% iOS, 44% Android) to this vulnerability, 33% of which are enterprise-focused. As of August 2017, 102 were available on the iOS and 75 on Google Play, with the Android apps being downloaded 180 million times.
Exploitation of the vulnerability is as simple as acquiring the default credentials (e.g. by downloading the SDK) and finding an application that uses hardcoded credentials. By using a tool such as YARA, an attacker can pull the Twilio account details and phone number associated with them; before using these to access the Twilio API where they can steal metadata, including messaging and voice files.
Remediation steps
Last edited: 17 February 2020 11:30 am