PT-2018-16356 · Signal · Signal Messenger For Android

Published

2018-12-10

·

Updated

2023-02-03

·

CVE-2018-3988

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Signal Messenger for Android version 4.24.8
Description The issue may expose private information when using "disappearing messages." If a user uses the photo feature available in the "attach file" menu, then Signal will leave the picture in its own cache directory, which is available to any application on the system.
Recommendations For Signal Messenger for Android version 4.24.8, consider clearing the cache directory after using the photo feature in "disappearing messages" to minimize the risk of private information exposure. As a temporary workaround, restrict access to the cache directory to prevent other applications from accessing the sensitive information.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2018-3988

Affected Products

Signal Messenger For Android