Simple Coding Error Exposing Data in 685 Apps, Affecting 180 Million Phones: Appthority

Advertisement
By Reuters | Updated: 10 November 2017 10:34 IST

A simple coding error in at least 685 apps put millions of smartphone users at risk of having some of their calls and text messages intercepted by hackers, cyber-security firm Appthority warned on Thursday.

Developers mistakenly coded credentials for accessing text messaging, calling and other services provided by Twilio Inc, said Appthority's director of security research, Seth Hardy. Hackers could access those credentials by reviewing the code in the apps, then gain access to data sent over those services, he said.

Affected apps include the AT&T Navigator app pre-installed on many Android phones and more than a dozen GPS navigation apps published by Telenav Inc. Such apps have been installed as many as 180 million times on Android phones and an unknown number of times on Apple's iOS-based devices.

Advertisement

Shares of Twilio slid nearly 7 percent after the Appthority report. Hackers covet Twilio credentials because they are used in a variety of apps that send text messages, process phone calls and handle other services. Hackers could access related data if they log into a developer's Twilio account, Hardy said.

Advertisement

Appthority, cautious not to tip off potential hackers, did not list all the apps that could be vulnerable. Twillio's website says its users include Uber Technologies Inc and Netflix Inc. However, large companies like those typically have security reviews that catch common coding errors like the one Appthority described.

There was no indication that Uber or Netflix were affected by the problem.

Advertisement

The findings highlight new threats posed by the increasing use of third-party services such as Twilio, which says on its website that it powers communications for more than 40,000 businesses worldwide. Developers can inadvertently introduce security vulnerabilities if they do not properly code or configure such services.

"This isn't just limited to Twilio. It's a common problem across third-party services," Hardy said. "We often notice that if they make a mistake with one service, they will do so with other services as well."

Advertisement

Appthority said it also warned Amazon.com Inc that it had found credentials for at least 902 developer accounts with cloud-service provider Amazon Web Services in a scan of 20,098 different apps.

Those credentials could be used to access app user data stored on Amazon, Hardy said.

A representative with Amazon declined comment.

One problem with third-party services is that developers often use the same account across multiple apps, similar to how consumers might use one email address for a variety of financial services and can have fraud problems at all of them if hackers compromise that single email account.

Appthority found Twilio credentials exposed in a now-defunct version of the AT&T Navigator mapping and GPS app. The AT&T app was a re-branded version of an app originally built by Telenav.

Appthority found that newer versions of the AT&T app appeared to be safe, but data sent over them could still be at risk if the developer of a related app is still using the same Twilio account. It said the same Twilio credentials were found coded in more than a dozen other Telenav apps.

AT&T and Telenav could not immediately be reached for comment.

The mistakes were caused by developers, not Twilio, Hardy said. Twilio's website warns developers that leaving credentials in apps could expose their accounts to hackers.

Twilio spokesman Trak Lord said the company has no evidence that hackers used credentials coded into apps to access customer data but was working with developers to change credentials on affected accounts.

The Twilio vulnerability only affects calls and texts made inside of apps that use its messaging services, including some business apps for recording phone calls such as Wrappup and RingDNA, according to Appthority's report. Wrappup an RingDNA could not immediately be reached for comment.

In a survey of 1,100 apps, Appthority found 685 problem apps that were linked to 85 affected Twilio accounts. That suggests the theft of credentials for one app's Twilio account could pose a security threat to all users of as many as eight other apps.

Twilio's shares closed down 6.8 percent at $25.93. Shares had rallied in pre-market trading after Twilio beat revenue expectations and raised its revenue forecast during an earnings report after the markets closed on Wednesday.

© Thomson Reuters 2017

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Twilio, Vulnerability, Appthority
Advertisement
Popular Mobile Brands
  1. Cloudflare Is Down Again For the Second Time in Weeks: See Affected Sites
  2. ACT Fibernet Launches New Broadband Plans With Free OTT Subscriptions
  3. Flipkart Buy Buy 2025 Sale: Nothing Phone 3, Phone 3a Deals Revealed
  4. HMD 101, HMD 100 With Built-In Radio Launched in India at These Prices
  5. Motorola Edge 70 With Pantone's 2026 Colour, Swarovski Crystals Launched
  6. OnePlus 15R Surfaces on Benchmarking Site Ahead of India Launch
  7. Nothing Phone 3a Lite Goes on Sale in India at This Price
  8. Vivo S50 Colour Options, Key Features Surface Online Ahead of Launch
  9. OTT Releases of the Week (Dec 1 – Dec 7): Know What to Watch
  10. Realme 16 Pro+ 5G New Leak Reveals Storage and Colour Variants
  1. Google’s Year in Search 2025: Top Trending Topics in India—From Gemini to Squid Games
  2. Vivo S50 Colour Options, Key Features Surface Online; Could Launch in India as Vivo V70
  3. CFTC Clears Path for Spot Crypto Trading on Regulated Platforms for the First Time
  4. Realme 16 Pro+ 5G Colour Options, Memory Configurations Leaked Again; Tipped to Launch With 7,000mAh Battery
  5. Cloudflare Outage Blocks Access to Several Websites Including BookMyShow, SpaceX, Coinbase
  6. Samsung Galaxy S26 Series to Offer Built-In Support for Company's 25W Magnetic Qi2 Charger: Report
  7. Airtel Discontinues Two Prepaid Recharge Packs in India With Data Benefits, Free Airtel Xtreme Play Subscription
  8. Samsung Galaxy Phones, Devices Are Now Available via Instamart With 10-Minute Instant Delivery
  9. NotebookLM App Gets an In-Built Camera, Lets Users Upload Images as a Source
  10. HMD 101 Launched in India With 1,000mAh Battery, Auto Call Recording Alongside HMD 100: Price, Features
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.