CVE-2016-10511: Twitter

Medium severity, CVSS 5.9. EPSS: 0.8% chance of exploitation in the next 30 days.

The Twitter iOS client versions 6.62 and 6.62.1 fail to validate Twitter's server certificates for the /1.1/help/settings.json configuration endpoint, permitting man-in-the-middle attackers the ability to view an application-only OAuth client token and potentially enable unreleased Twitter iOS app features.

Affected products

  • Twitter Twitter: version 6.62 only; version 6.62.1 only

Published 2017-09-18. Last modified 2026-06-17.