ZeroHour

CVE-2024-39891

KEVmass

Unauthenticated Phone-Number Enumeration in Twilio Authy API (Android/iOS)

CISA: Twilio Authy Information Disclosure Vulnerability

CVSS 3.1
5.3 medium
EPSS
2%p76
Published
()
KEV added
AI analysis

An unauthenticated endpoint in the Twilio Authy API, reachable through Authy for Android before 25.1.0 and Authy for iOS before 26.1.0, disclosed whether arbitrary phone numbers were registered with the Authy service — an information-disclosure flaw tracked as CWE-203. An attacker could send a stream of phone-number queries to the endpoint over the network with no authentication, privileges, or user interaction, and the API responses revealed the registration status of each number. The attacker's gain was bulk enumeration of which phone numbers use Authy, which is valuable for targeting follow-on phishing, social engineering, or SIM-swap attacks; Authy accounts themselves were not compromised and no credentials or authentication data were exposed. Any user of the affected Android or iOS apps whose phone number could be queried was potentially affected, since the flaw lay in the API's access control rather than in the apps' token generation. The flaw was exploited in the wild in June 2024 and was added to CISA's Known Exploited Vulnerabilities catalog on 2024-07-23 (EPSS currently estimates a 1.7% probability of exploitation in the next 30 days); no public PoC is known.

What to do: Update the Authy Android app to version 25.1.0 or later and the Authy iOS app to version 26.1.0 or later per Twilio's guidance, which closes the unauthenticated endpoint's permissive responses. No account compromise was reported, but users and defenders should stay alert to targeted phishing or social engineering that could leverage knowledge of a phone number's Authy registration, and organizations tracking CISA KEV should apply vendor mitigations or discontinue use of the product if mitigations are unavailable.

Affected
twilio Authy for Androidbefore 25.1.0
twilio Authy for iOSbefore 26.1.0
twilio Authy / Authy Authenticator (as listed in CPE)
Estimated exposure
mass≈ tens of millions of Authy app users (large consumer/enterprise 2FA install base) — Twilio Authy is one of the most widely deployed consumer and enterprise two-factor authentication apps, with a user base historically reported in the tens of millions, and the unauthenticated endpoint allowed bulk enumeration of any phone…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-number data, as exploited in the wild in June 2024. Specifically, the endpoint accepted a stream of requests containing phone numbers, and responded with information about whether each phone number was registered with Authy. (Authy accounts were not compromised, however.)

CISA Known Exploited Vulnerability
Affected
Twilio Authy
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
twilio
Products
authy, authy authenticator
Weakness
CWE-203
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news