Saturday, March 15, 2025
HomeCVE/vulnerability17 Years Old Hacker Finds Critical Flaw in Signal App that Allows...

17 Years Old Hacker Finds Critical Flaw in Signal App that Allows Anyone to Bypass Password & Screen lock in iOS

Published on

SIEM as a Service

Follow Us on Google News

A 17 Years old Hacker who inspired by Edward Snowden discovered a critical vulnerability in Signal app that allows anyone to Bypass Authentication of Lock Screen in iOS.

Signal is an encrypted communications app for Android and iOS. A desktop version is also available for Linux, Windows, and macOS.

It allows users to send one-to-one and group messages, which can include files, voice notes, images, and videos, and make one-to-one voice and video calls.

This vulnerability works based on the click sequence include app opening, clicking on cancel, and using the home button.

Signal iOS app allows lets anyone bypass the password and TouchID authentication protections in iOS.

Initially the bug was reported in Signal version 2.23 by the researcher but the Signal security team partially fixed it and released version 2.23.1.1.

Users can use following steps to trigger the bug in version 2.23:

  1. Open Signal
  2. Click cancel button
  3. Click home button
  4. Open Signal again
  5. You can see Signal main screen without having been asked for the Password or TouchID

But the fixed version 2.23.1.1 still vulnerable to screen locker bypass using different click sequence.

While users can use following steps to trigger the bug in version 2.23.1.1 (the one that contains the partial fix):

  1. Open Signal
  2. Click cancel button
  3. Click home button
  4. Double click on the home button
  5. Close Signal app
  6. Open Signal App
  7. Click cancel button
  8. Click once the home button
  9. Open Signal
  10. You can see Signal main screen without having been asked for the Password or TouchID

He reported the second bug aswell to the security team and version 2.23.2 finally fixed the problem.

Also, he said, From data protection point of view Signal is safer than other Instant Messengers applications (eg. WhatsApp) which, even using end-to-end data encryption like Signal, retain very important metadata which could hand over to governments in response to a request.

Finally, new version 2.23.2 has been released and assign the CVE-2018-9840.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Hackers Exploiting Exposed Jupyter Notebooks to Deploy Cryptominers

Cado Security Labs has identified a sophisticated cryptomining campaign exploiting misconfigured Jupyter Notebooks, targeting...

AWS SNS Exploited for Data Exfiltration and Phishing Attacks

Amazon Web Services' Simple Notification Service (AWS SNS) is a versatile cloud-based pub/sub service...

Edimax Camera RCE Vulnerability Exploited to Spread Mirai Malware

A recent alert from the Akamai Security Intelligence and Response Team (SIRT) has highlighted...

Cisco Warns of Critical IOS XR Vulnerability Enabling DoS Attacks

Cisco has issued a security advisory warning of a vulnerability in its IOS XR...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Cisco Warns of Critical IOS XR Vulnerability Enabling DoS Attacks

Cisco has issued a security advisory warning of a vulnerability in its IOS XR...

Critical ruby-saml Vulnerabilities Allow Attackers to Bypass Authentication

A critical security vulnerability has been identified in the ruby-saml library, a popular tool...

Apache NiFi Vulnerability Exposes MongoDB Credentials to Attackers

A critical security vulnerability has been identified in Apache NiFi, a popular open-source data...