CVE-2024-39891
KEVmassUnauthenticated Phone-Number Enumeration in Twilio Authy API (Android/iOS)
CISA: Twilio Authy Information Disclosure Vulnerability
An unauthenticated endpoint in the Twilio Authy API, reachable through Authy for Android before 25.1.0 and Authy for iOS before 26.1.0, disclosed whether arbitrary phone numbers were registered with the Authy service — an information-disclosure flaw tracked as CWE-203. An attacker could send a stream of phone-number queries to the endpoint over the network with no authentication, privileges, or user interaction, and the API responses revealed the registration status of each number. The attacker's gain was bulk enumeration of which phone numbers use Authy, which is valuable for targeting follow-on phishing, social engineering, or SIM-swap attacks; Authy accounts themselves were not compromised and no credentials or authentication data were exposed. Any user of the affected Android or iOS apps whose phone number could be queried was potentially affected, since the flaw lay in the API's access control rather than in the apps' token generation. The flaw was exploited in the wild in June 2024 and was added to CISA's Known Exploited Vulnerabilities catalog on 2024-07-23 (EPSS currently estimates a 1.7% probability of exploitation in the next 30 days); no public PoC is known.
What to do: Update the Authy Android app to version 25.1.0 or later and the Authy iOS app to version 26.1.0 or later per Twilio's guidance, which closes the unauthenticated endpoint's permissive responses. No account compromise was reported, but users and defenders should stay alert to targeted phishing or social engineering that could leverage knowledge of a phone number's Authy registration, and organizations tracking CISA KEV should apply vendor mitigations or discontinue use of the product if mitigations are unavailable.
| twilio Authy for Android | before 25.1.0 |
| twilio Authy for iOS | before 26.1.0 |
| twilio Authy / Authy Authenticator (as listed in CPE) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-number data, as exploited in the wild in June 2024. Specifically, the endpoint accepted a stream of requests containing phone numbers, and responded with information about whether each phone number was registered with Authy. (Authy accounts were not compromised, however.)
- Affected
- Twilio Authy
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- twilio
- Products
- authy, authy authenticator
- Weakness
- CWE-203
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N