PT-2023-19386 · Signal · Signal Desktop+1

Published

2023-01-23

·

Updated

2025-04-02

·

CVE-2023-24069

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Signal Desktop versions prior to 6.2.0
Description The issue allows an attacker to obtain potentially sensitive attachments sent in messages from the attachments.noindex directory. Cached attachments are not effectively cleared. In some cases, even after a self-initiated file deletion, an attacker can still recover the file if it was previously replied to in a conversation. Local filesystem access is needed by the attacker.
Recommendations For Signal Desktop versions prior to 6.2.0, update to version 6.2.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the attachments.noindex directory to minimize the risk of exploitation. Avoid using the desktop application to store sensitive attachments until the issue is resolved.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2023-24069

Affected Products

Esignal
Signal Desktop