TweetDeck back online, questionable security flaw fix in place

TweetDeck
Get the hell out of Dodge

Update 2: TechRadar staffers are reporting TweetDeck's fix isn't working, meaning logging in and logging out won't protect you from someone retweeting from your account, or worse.

We suggest staying clear of TweetDeck, revoking access to your Twitter if you have it set up, and changing your password (just to be safe) until we get official word all is well.

Update 1: TweetDeck access is back, according to a tweet the beleaguered service sent after an hour-plus security kerfuffle.

"We've verified our security fix and have turned TweetDeck services back on for all users. Sorry for any inconvenience," TweetDeck wrote.

It's unclear whether users must log in, log out and finally log back in to apply "our security fix," one that supposedly keeps hackers who can supplant JavaScript code at bay.

We've asked TweetDeck to confirm if that's the case or not, but we suggest you do so just to be safe.

Original article below...

TweetDeck has been taken offline in order to address a security issue, and users can't log into the service (Update: It's back!).

The development comes after the tweet-posting web app had advised users to log out and log back in to apply a fix to a security vulnerability. If you're still in TweetDeck, get out now.

An XSS security vulnerability was spotted earlier in the day, a flaw that potentially gave hackers access to users accounts when they were logged in, according to Mashable. Users on Chrome seemed to be the only ones affected.

Damn pop-ups

As noted by The Verge, the vulnerability lets hackers remotely access JavaScript code and implant their own.

So far attackers seem to be sticking to annoying pop-up windows and spamming retweets, but they could potentially do much worse damage.

Again, only users of the TweetDeck web application on Chrome seem to be affected, but it's advisable to log out of the service no matter where you're accessing it.

When asked for comment, a Twitter spokesman told TechRadar it directing people to the @TweetDeck tweets coming out about the situation.

Michelle Fitzsimmons

Michelle was previously a news editor at TechRadar, leading consumer tech news and reviews. Michelle is now a Content Strategist at Facebook.  A versatile, highly effective content writer and skilled editor with a keen eye for detail, Michelle is a collaborative problem solver and covered everything from smartwatches and microprocessors to VR and self-driving cars.

Latest in Security
A graphic showing someone on a tablet working through a supply chain.
Security issue in open source software leaves businesses concerned for systems
ransomware avast
One of the most powerful ransomware hacks around has been cracked using some serious GPU power
person at a computer
Infamous ransomware hackers reveal new tool to brute-force VPNs
person at a computer
Many workers are overconfident at spotting phishing attacks
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft 365 accounts are under attack from new malware spoofing popular work apps
Data Breach
Thousands of healthcare records exposed online, including private patient information
Latest in News
Panos Panay and Alexa Plus
Amazon's Panos Panay teases future Alexa+ devices from speakers to possible wearables
Metroid Prime 4
I reckon the Nintendo Switch 2 could launch with Metroid Prime 4 – here’s why
Samsung Galaxy Z Fold 6
New rumors predict a foldable iPhone will launch next year – and cost almost twice as much as the iPhone 16 Pro Max
Pebble smartwatch countdown
Pebble confirms its smartwatch announcement is just hours away
Logo of YouTube Shorts
Is YouTube auto-playing Shorts when you open the app? Well, you’re not alone - here’s how to fix it
Google DeepMind panel discussion
“More sovereignty and protection” - Google goes all-in on UK AI with data residency, upskilling projects, and startup investments