[URGENT] Opportunity to publish tweets on any twitters account
High
X
X (Formerly Twitter)
Submitted None
Team Summary
Official summary from X (Formerly Twitter)
The reporter discovered a flaw in the handling of Twitter Ads Studio requests which allowed an attacker to tweet as any user. By sharing media with a victim user and then modifying the post request with the victim's account ID the media in question would be posted from the victim's account. This bug was patched immediately after being triaged and no evidence was found of the flaw being exploited by anyone other than the reporter.
Actions:
Reported by
kedrischh
Report Details
Additional information and metadata
State
Closed
Substate
Resolved