Incorrect details on OAuth permissions screen allows DMs to be read without permission
Team Summary
Official summary from X (Formerly Twitter)
The reporter discovered that when a select set of applications are authenticated using a PIN or non-intended OAuth flow, the permission dialog that is shown may not show the permissions that the application has. We do not believe anyone was mislead by the permissions that these applications had or that their data was unintentionally accessed by the Twitter for iPhone or Twitter for Google TV applications as those applications use other authentication flows. To our knowledge, there was not a breach of anyone's information due to this issue. There are no actions people need to take at this time.
Vulnerability Details
Technical details and impact analysis
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$2940.00
Submitted
Weakness
Privacy Violation