CVE-2020-24655

MEDIUM

Twilio Authy <24.3.7 - Privilege Escalation

Title source: llm
STIX 2.1

Description

A race condition in the Twilio Authy 2-Factor Authentication application before 24.3.7 for Android allows a user to potentially approve/deny an access request prior to unlocking the application with a PIN on older Android devices (effectively bypassing the PIN requirement).

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://www.twilio.com/changelog

Scores

CVSS v3 5.1
EPSS 0.0022
EPSS Percentile 12.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-362
Status published
Products (1)
twilio/authy_2-factor_authentication 24.3.7
Published Sep 10, 2020
Tracked Since Feb 18, 2026