Twitter Subscriptions Information Disclosure

Disclosed: 2023-09-18 19:33:19 By mirhat To x
Medium
Vulnerability Details
**Summary:** Hi team, I was scrolling on Twitter connected from US location, and a Tweet appeared on my timeline; I couldn't see the tweet because it is only visible to subscribers. However I was able to extract the images from that tweet even though I'm not a subscriber **Description:** A subscriber only tweet of MrBeast appeared on my timeline (which i can't see) {F2487967} Clicking on the quotes button revealed the images and the tweet content which should be invisible to me. **Steps To Reproduce:** 1. Go to https://twitter.com/MrBeast/status/1678121172196630531 1. Ensure that you are not a subscriber therefore cannot see the tweet 1. Click on quotes button and see the tweet and images ## Supporting Material/References: POC video: ████ ## Impact Information disclosure
Actions
View on HackerOne
Report Stats
  • Report ID: 2063636
  • State: Closed
  • Substate: resolved
  • Upvotes: 25
Share this report