ZeroHour

Vulnerabilities

2 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-39891
Unauthenticated Phone-Number Enumeration in Twilio Authy API (Android/iOS)

An unauthenticated endpoint in the Twilio Authy API, reachable through Authy for Android before 25.1.0 and Authy for iOS before 26.1.0, disclosed whether arbitrary phone numbers were registered with the Authy service — an information-disclosure flaw tracked as CWE-203. An attacker could send a stream of phone-number queries to the endpoint over the network with no authentication, privileges, or user interaction, and the API responses revealed the registration status of each number. The attacker's gain was bulk enumeration of which phone numbers use Authy, which is valuable for targeting follow-on phishing, social engineering, or SIM-swap attacks; Authy accounts themselves were not compromised and no credentials or authentication data were exposed. Any user of the affected Android or iOS apps whose phone number could be queried was potentially affected, since the flaw lay in the API's access control rather than in the apps' token generation. The flaw was exploited in the wild in June 2024 and was added to CISA's Known Exploited Vulnerabilities catalog on 2024-07-23 (EPSS currently estimates a 1.7% probability of exploitation in the next 30 days); no public PoC is known.

Do: Update the Authy Android app to version 25.1.0 or later and the Authy iOS app to version 26.1.0 or later per Twilio's guidance, which closes the unauthenticated endpoint's permissive responses. No account compromise was reported, but users and defenders should stay alert to targeted phishing or social engineering that could leverage knowledge of a phone number's Authy registration, and organizations tracking CISA KEV should apply vendor mitigations or discontinue use of the product if mitigations are unavailable.

5.32% KEV
  • twilio Authy for Android before 25.1.0
  • twilio Authy for iOS before 26.1.0
  • twilio Authy / Authy Authenticator (as listed in CPE)
mass≈ tens of millions of Authy app users (large consumer/enterprise 2FA install base)
CVE-2020-24655
A race condition in the Twilio Authy 2-Factor Authentication application before 24.3.7 for Android allows a user to potentially approve/deny an access request p

A race condition in the Twilio Authy 2-Factor Authentication application before 24.3.7 for Android allows a user to potentially approve/deny an access request prior to unlocking the application with a PIN on older Android devices (effectively bypassing the PIN requirement).

NVD description · AI analysis pending
5.1<1%
  • twilio authy 2-factor authentication