TweetDeck back online, questionable security flaw fix in place

TweetDeck
Get the hell out of Dodge

Update 2: TechRadar staffers are reporting TweetDeck's fix isn't working, meaning logging in and logging out won't protect you from someone retweeting from your account, or worse.

We suggest staying clear of TweetDeck, revoking access to your Twitter if you have it set up, and changing your password (just to be safe) until we get official word all is well.

Update 1: TweetDeck access is back, according to a tweet the beleaguered service sent after an hour-plus security kerfuffle.

"We've verified our security fix and have turned TweetDeck services back on for all users. Sorry for any inconvenience," TweetDeck wrote.

It's unclear whether users must log in, log out and finally log back in to apply "our security fix," one that supposedly keeps hackers who can supplant JavaScript code at bay.

We've asked TweetDeck to confirm if that's the case or not, but we suggest you do so just to be safe.

Original article below...

TweetDeck has been taken offline in order to address a security issue, and users can't log into the service (Update: It's back!).

The development comes after the tweet-posting web app had advised users to log out and log back in to apply a fix to a security vulnerability. If you're still in TweetDeck, get out now.

An XSS security vulnerability was spotted earlier in the day, a flaw that potentially gave hackers access to users accounts when they were logged in, according to Mashable. Users on Chrome seemed to be the only ones affected.

Damn pop-ups

As noted by The Verge, the vulnerability lets hackers remotely access JavaScript code and implant their own.

So far attackers seem to be sticking to annoying pop-up windows and spamming retweets, but they could potentially do much worse damage.

Again, only users of the TweetDeck web application on Chrome seem to be affected, but it's advisable to log out of the service no matter where you're accessing it.

When asked for comment, a Twitter spokesman told TechRadar it directing people to the @TweetDeck tweets coming out about the situation.

Michelle Fitzsimmons

Michelle was previously a news editor at TechRadar, leading consumer tech news and reviews. Michelle is now a Content Strategist at Facebook.  A versatile, highly effective content writer and skilled editor with a keen eye for detail, Michelle is a collaborative problem solver and covered everything from smartwatches and microprocessors to VR and self-driving cars.

Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring