Authy Android 25.1.0 이전 버전 및 Authy iOS 26.1.0 이전 버전에서 접근하는 Twilio Authy API의 인증되지 않은 엔드포인트가 특정 전화번호 데이터에 대한 접근을 제공했으며, 이는 2024년 6월 실제 환경에서 악용되었습니다. 구체적으로 이 엔드포인트는 전화번호가 포함된 연속된 요청을 수락하고 각 전화번호가 Authy에 등록되어 있는지에 관한 정보로 응답했습니다. 다만 Authy 계정은 침해되지 않았습니다.
Authy Android 25.1.0 이전 버전 및 Authy iOS 26.1.0 이전 버전에서 접근하는 Twilio Authy API의 인증되지 않은 엔드포인트가 특정 전화번호 데이터에 대한 접근을 제공했으며, 이는 2024년 6월 실제 환경에서 악용되었습니다. 구체적으로 이 엔드포인트는 전화번호가 포함된 연속된 요청을 수락하고 각 전화번호가 Authy에 등록되어 있는지에 관한 정보로 응답했습니다. 다만 Authy 계정은 침해되지 않았습니다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-number data, as exploited in the wild in June 2024. Specifically, the endpoint accepted a stream of requests containing phone numbers, and responded with information about whether each phone number was registered with Authy. (Authy accounts were not compromised, however.)