Description
In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-number data. (Authy accounts were not compromised, however.)
References
https://cwe.mitre.org/data/definitions/203.html
https://www.twilio.com/docs/usage/security/reporting-vulnerabilities
https://www.twilio.com/en-us/changelog