Bypass t.co link shortener in Twitter direct messages
Low
X
X (Formerly Twitter)
Submitted None
Team Summary
Official summary from X (Formerly Twitter)
The researcher demonstrated a way to create a link that will not be replaced with safe shortened t.co url, by sending Direct Messages containing more than 50 t.co links to another Twitter user. If the recipient views the message using Twitter’s Android app, and clicks the 51st link in the attacker’s message, they will be redirected to the target website without first passing through Twitter’s t.co link shortener.
Actions:
Reported by
iambouali
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Business Logic Errors