Vulnerability Intelligence Report
Twilio Authy Information Disclosure Vulnerability
CVE-2024-39891
In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-number data, as exploited in the wild in June 2024. Specifically, the endpoint accepted a stream of requests containing phone numbers, and responded with information about whether each phone number was registered with Authy. (Authy accounts were not compromised, however.)
CISA KEV
SSVC: Active Exploitation
Automatable
CVSS Base Score
5.3
MEDIUM
Exploitability:3.9
Impact Score:1.5
EPSS Probability:1.48%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-203 ↗CWE-203 Observable Discrepancy
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| twilio | authy | all |
| twilio | authy_authenticator | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2024-07-02T00:00:00 |
| Published | 2024-07-02T00:00:00 |
| Last Updated | 2025-10-21T22:55:50 |
Community Chatter & Buzz