Jump to content

WordPress says iOS app bug exposed account tokens to third-parties


NelsonG

Recommended Posts

WordPress said it’s fixed a bug in its iOS app that inadvertently exposed account tokens to third-party sites.

In an email to customers seen by TechCrunch, the content management giant said it “uncovered an issue with the WordPress iOS application with how it handles security credentials.” The company has disconnected affected accounts from the app “as a precaution.” The company’s Android app was not affected.

Although no usernames and passwords were involved, the app in some cases inadvertently sent sensitive account tokens to third-parties.

These account tokens are small bits of code that allow you to stay logged into an app or service without having to enter your password every time. But if leaked or stolen, an account token can give anyone access to your account without needing your password.

After reaching out to Automattic, the company’s parent, we’ve gained some additional clarity. In short, the bug was found in how images were fetched from private WordPress sites hosting images by other sites. If a private WordPress site had a post or a page with an image hosted on Flickr, for example, the app would send along a WordPress account token to Flickr when fetching the image.

That’s not how it’s meant to work. That meant account tokens could appear in the logs of third-party companies, which could expose unscrupulous individuals to target WordPress accounts. That said, the risk to accounts is minimal and users shouldn’t be overly worried.

All WordPress iOS users with private sites had their account tokens reset — so there’s no need to change your password.

“Our engineers discovered this bug in the iOS app and we have no indication it was ever exploited,” said a WordPress spokesperson in an email to TechCrunch. “The first affected version was released in January 2017, and version 11.9.1 released on March 15, 2019 fixed the issue.”

WordPress didn’t immediately say how many customers were affected, but mobile insights company Sensor Tower said in an email that the app was installed 9.3 million times on iOS since 2012, with about 1.3 million installs last year.

Users should update their app as soon as possible.

Techcrunch?d=2mJPEYqXBVI Techcrunch?d=7Q72WNTAKBA Techcrunch?d=yIl2AUoC8zA Techcrunch?i=LG_yCYrkqKU:T-DCsLTr2Gg:-BT Techcrunch?d=qj6IDK7rITs
LG_yCYrkqKU

View the full article

Link to comment
Share on other sites

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Our picks

    • Wait, Burning Man is going online-only? What does that even look like?
      You could have been forgiven for missing the announcement that actual physical Burning Man has been canceled for this year, if not next. Firstly, the nonprofit Burning Man organization, known affectionately to insiders as the Borg, posted it after 5 p.m. PT Friday. That, even in the COVID-19 era, is the traditional time to push out news when you don't want much media attention. 
      But secondly, you may have missed its cancellation because the Borg is being careful not to use the C-word. The announcement was neutrally titled "The Burning Man Multiverse in 2020." Even as it offers refunds to early ticket buyers, considers layoffs and other belt-tightening measures, and can't even commit to a physical event in 2021, the Borg is making lemonade by focusing on an online-only version of Black Rock City this coming August.    Read more...
      More about Burning Man, Tech, Web Culture, and Live EventsView the full article
      • 0 replies
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
×
×
  • Create New...