Thursday, May 15, 2025
HomeCVE/vulnerability17 Years Old Hacker Finds Critical Flaw in Signal App that Allows...

17 Years Old Hacker Finds Critical Flaw in Signal App that Allows Anyone to Bypass Password & Screen lock in iOS

Published on

SIEM as a Service

Follow Us on Google News

A 17 Years old Hacker who inspired by Edward Snowden discovered a critical vulnerability in Signal app that allows anyone to Bypass Authentication of Lock Screen in iOS.

Signal is an encrypted communications app for Android and iOS. A desktop version is also available for Linux, Windows, and macOS.

It allows users to send one-to-one and group messages, which can include files, voice notes, images, and videos, and make one-to-one voice and video calls.

- Advertisement - Google News

This vulnerability works based on the click sequence include app opening, clicking on cancel, and using the home button.

Signal iOS app allows lets anyone bypass the password and TouchID authentication protections in iOS.

Initially the bug was reported in Signal version 2.23 by the researcher but the Signal security team partially fixed it and released version 2.23.1.1.

Users can use following steps to trigger the bug in version 2.23:

  1. Open Signal
  2. Click cancel button
  3. Click home button
  4. Open Signal again
  5. You can see Signal main screen without having been asked for the Password or TouchID

But the fixed version 2.23.1.1 still vulnerable to screen locker bypass using different click sequence.

While users can use following steps to trigger the bug in version 2.23.1.1 (the one that contains the partial fix):

  1. Open Signal
  2. Click cancel button
  3. Click home button
  4. Double click on the home button
  5. Close Signal app
  6. Open Signal App
  7. Click cancel button
  8. Click once the home button
  9. Open Signal
  10. You can see Signal main screen without having been asked for the Password or TouchID

He reported the second bug aswell to the security team and version 2.23.2 finally fixed the problem.

Also, he said, From data protection point of view Signal is safer than other Instant Messengers applications (eg. WhatsApp) which, even using end-to-end data encryption like Signal, retain very important metadata which could hand over to governments in response to a request.

Finally, new version 2.23.2 has been released and assign the CVE-2018-9840.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Threat Actors Leverage Weaponized HTML Files to Deliver Horabot Malware

A recent discovery by FortiGuard Labs has unveiled a cunning phishing campaign orchestrated by...

TA406 Hackers Target Government Entities to Steal Login Credentials

The North Korean state-sponsored threat actor TA406, also tracked as Opal Sleet and Konni,...

Google Threat Intelligence Releases Actionable Threat Hunting Technique for Malicious .desktop Files

Google Threat Intelligence has unveiled a series of sophisticated threat hunting techniques to detect...

New Adobe Photoshop Vulnerability Enables Arbitrary Code Execution

Adobe has released critical security updates addressing three high-severity vulnerabilities (CVE-2025-30324, CVE-2025-30325, CVE-2025-30326) in...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Phishing Campaign Uses Blob URLs to Bypass Email Security and Avoid Detection

Cybersecurity researchers at Cofense Intelligence have identified a sophisticated phishing tactic leveraging Blob URIs...

PoC Code Published for Linux nftables Security Vulnerability

Security researchers have published proof-of-concept (PoC) exploit code for CVE-2024-26809, a high-severity double-free vulnerability in...

UK Government to Shift Away from Passwords in New Security Move

UK government has unveiled plans to implement passkey technology across its digital services later...