Open Whisper Signal (aka Signal-Desktop) before 1.15.0-beta.10 allows information leakage.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://n0sign4l.blogspot.com/2018/08/advisory-id-n0sign4l-002-risk-level-4-5.html?m=1 | third party advisory exploit |
https://www.youtube.com/watch?v=oSJscEei5SE&app=desktop | third party advisory exploit |