A 17 Years old Hacker who inspired by Edward Snowden discovered a critical vulnerability in Signal app that allows anyone to Bypass Authentication of Lock Screen in iOS.
Signal is an encrypted communications app for Android and iOS. A desktop version is also available for Linux, Windows, and macOS.
It allows users to send one-to-one and group messages, which can include files, voice notes, images, and videos, and make one-to-one voice and video calls.
This vulnerability works based on the click sequence include app opening, clicking on cancel, and using the home button.
Signal iOS app allows lets anyone bypass the password and TouchID authentication protections in iOS.
Initially the bug was reported in Signal version 2.23 by the researcher but the Signal security team partially fixed it and released version 2.23.1.1.
Users can use following steps to trigger the bug in version 2.23:
But the fixed version 2.23.1.1 still vulnerable to screen locker bypass using different click sequence.
While users can use following steps to trigger the bug in version 2.23.1.1 (the one that contains the partial fix):
He reported the second bug aswell to the security team and version 2.23.2 finally fixed the problem.
Also, he said, From data protection point of view Signal is safer than other Instant Messengers applications (eg. WhatsApp) which, even using end-to-end data encryption like Signal, retain very important metadata which could hand over to governments in response to a request.
Finally, new version 2.23.2 has been released and assign the CVE-2018-9840.
Ivanti has issued an urgent security advisory for CVE-2025-22457, a critical vulnerability impacting Ivanti Connect…
A concerning malware campaign was disclosed by the AhnLab Security Intelligence Center (ASEC), revealing how…
EncryptHub, a rapidly evolving cybercriminal entity, has come under intense scrutiny following revelations of operational…
A sophisticated phishing campaign, dubbed "PoisonSeed," has been identified targeting customer relationship management (CRM) and…
A surge in phishing text messages claiming unpaid tolls has been linked to a massive…
The State Bar of Texas has confirmed a data breach following the detection of unauthorized…