PT-2018-19065 · Open Whisper Systems · Open Whisper Signal

Published

2018-04-10

·

Updated

2019-10-03

·

CVE-2018-9840

CVSS v3.1

6.8

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Open Whisper Signal versions prior to 2.23.2
Description The issue allows physically proximate attackers to bypass the screen locker feature via certain rapid sequences of actions. This includes opening the app, clicking on cancel, and using the home button.
Recommendations For versions prior to 2.23.2, update to version 2.23.2 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2018-9840

Affected Products

Open Whisper Signal