Thursday, December 5, 2024
HomeCVE/vulnerability17 Years Old Hacker Finds Critical Flaw in Signal App that Allows...

17 Years Old Hacker Finds Critical Flaw in Signal App that Allows Anyone to Bypass Password & Screen lock in iOS

Published on

SIEM as a Service

A 17 Years old Hacker who inspired by Edward Snowden discovered a critical vulnerability in Signal app that allows anyone to Bypass Authentication of Lock Screen in iOS.

Signal is an encrypted communications app for Android and iOS. A desktop version is also available for Linux, Windows, and macOS.

It allows users to send one-to-one and group messages, which can include files, voice notes, images, and videos, and make one-to-one voice and video calls.

- Advertisement - SIEM as a Service

This vulnerability works based on the click sequence include app opening, clicking on cancel, and using the home button.

Signal iOS app allows lets anyone bypass the password and TouchID authentication protections in iOS.

Initially the bug was reported in Signal version 2.23 by the researcher but the Signal security team partially fixed it and released version 2.23.1.1.

Users can use following steps to trigger the bug in version 2.23:

  1. Open Signal
  2. Click cancel button
  3. Click home button
  4. Open Signal again
  5. You can see Signal main screen without having been asked for the Password or TouchID

But the fixed version 2.23.1.1 still vulnerable to screen locker bypass using different click sequence.

While users can use following steps to trigger the bug in version 2.23.1.1 (the one that contains the partial fix):

  1. Open Signal
  2. Click cancel button
  3. Click home button
  4. Double click on the home button
  5. Close Signal app
  6. Open Signal App
  7. Click cancel button
  8. Click once the home button
  9. Open Signal
  10. You can see Signal main screen without having been asked for the Password or TouchID

He reported the second bug aswell to the security team and version 2.23.2 finally fixed the problem.

Also, he said, From data protection point of view Signal is safer than other Instant Messengers applications (eg. WhatsApp) which, even using end-to-end data encryption like Signal, retain very important metadata which could hand over to governments in response to a request.

Finally, new version 2.23.2 has been released and assign the CVE-2018-9840.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

HCL DevOps Deploy / Launch Vulnerability Let Embed arbitrary HTML tags

Recently identified by security researchers, a new vulnerability in HCL DevOps Deploy and HCL...

CISA Warns of Zyxel Firewalls, CyberPanel, North Grid, & ProjectSend Flaws Exploited in Wild

The Cybersecurity and Infrastructure Security Agency (CISA) has issued warnings about several vulnerabilities being...

HackSynth : Autonomous Pentesting Framework For Simulating Cyberattacks

HackSynth is an autonomous penetration testing agent that leverages Large Language Models (LLMs) to...

Fuji Electric Indonesia Hit by Ransomware Attack

Fuji Electric Indonesia has fallen victim to a ransomware attack, impacting its operations and...

API Security Webinar

72 Hours to Audit-Ready API Security

APIs present a unique challenge in this landscape, as risk assessment and mitigation are often hindered by incomplete API inventories and insufficient documentation.

Join Vivek Gopalan, VP of Products at Indusface, in this insightful webinar as he unveils a practical framework for discovering, assessing, and addressing open API vulnerabilities within just 72 hours.

Discussion points

API Discovery: Techniques to identify and map your public APIs comprehensively.
Vulnerability Scanning: Best practices for API vulnerability analysis and penetration testing.
Clean Reporting: Steps to generate a clean, audit-ready vulnerability report within 72 hours.

More like this

HCL DevOps Deploy / Launch Vulnerability Let Embed arbitrary HTML tags

Recently identified by security researchers, a new vulnerability in HCL DevOps Deploy and HCL...

CISA Warns of Zyxel Firewalls, CyberPanel, North Grid, & ProjectSend Flaws Exploited in Wild

The Cybersecurity and Infrastructure Security Agency (CISA) has issued warnings about several vulnerabilities being...

Thinkware Cloud APK Vulnerability Allows Code Execution With Elevated Privileges

A critical vulnerability identified as CVE-2024–53614 has been discovered in the Thinkware Cloud APK...