VYPR

Tweetbot

by Tapbots

CVEs (1)

  • CVE-2013-5726Nov 12, 2013
    risk 0.00cvss epss 0.00

    Tweetbot 1.3.3 for Mac, and 2.8.5 for iPad and iPhone, does not require confirmation of (1) follow or (2) favorite actions, which allows remote attackers to automatically force the user to perform undesired actions, as demonstrated via the tweetbot:///follow/ URL.