An improper access control vulnerability exists prior to v6 that could allow an attacker to break the E2E encryption of a chat room by a user changing the group key of a chat room.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
Link | Tags |
---|---|
https://hackerone.com/reports/1757663 | issue tracking third party advisory |