News: 1697486413

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Signal shoots down zero-day rumors, finds 'no evidence' of device takeover

(2023/10/16)


Signal has denied a "vague viral reports" of a zero-day vulnerability in its Generate Links Previews that could allow device takeover.

In a late Sunday night post on the site formerly known as Twitter, Signal said it conducted a "responsible investigation" and found " [1]no evidence that suggests this vulnerability is real nor has any additional info been shared via our official reporting channels."

PSA: we have seen the vague viral reports alleging a Signal 0-day vulnerability.After responsible investigation *we have no evidence that suggests this vulnerability is real* nor has any additional info been shared via our official reporting channels. — Signal (@signalapp) [2]October 16, 2023

"We also checked with people across US Government, since the copy-paste report claimed USG as a source," according to [3]Signal . "Those we spoke to have no info suggesting this is a valid claim."

The rumors started on Sunday with several well-known security [4]researchers and [5]security folk warning about the alleged remote code execution bug.

"Been hearing whispers all weekend, some from people who I'd *definitely* listen to, of a remote execution 0day in the Signal desktop and possibly also mobile app. Mitigation is supposedly to disable link previews (under settings->chats)," [6]said cryptography expert Matt Blaze on Mastodon.

[7]

"I have no more details," he opined. "What I've heard doesn't completely make sense, but disabling link previews should be at worst harmless and seems prudent until this is clarified.

[8]

[9]

After the messaging app refuted the zero-day claim, some including Blaze said it appeared to be related to [10]CVE-2023-4863 , a heap buffer overflow in libwebp that affected any software that used the WebP image library.

Several web browsers (Google Chrome, Mozilla Firefox, Brave, Tor, and more) along with operating systems (Ubuntu, SUSE, Oracle, and Amazon and other) and applications using Chromium-based Electron including Signal, Telegram and Slack all [11]issued fixes last month.

[12]Signal adopts new alphabet jumble to protect chats from quantum computers

[13]Chrome, Firefox and more caught with their WebP down, offer hasty patch-up

[14]It's 2023 and Microsoft WordPad can be exploited to hijack vulnerable systems

[15]Another security update, Apple? You're really keeping up with your tech rivals

A Signal spokesperson wouldn't confirm that the rumored bug was related to CVE-2023-4863, but told The Register : "If it is related to CVE-2023-4863, the webp vulnerability, Signal patched that weeks ago and the latest versions of Signal have all been running that patch for some time."

Regardless, it's a good reminder to update software and apps in a timely manner. And, as, several infosec insiders pointed out: to be safe, [16]turn off features that you aren't using. And [17]don't panic .

[18]

Huntress senior security researcher John Hammond told The Register that he hasn't seen anything to indicate a Signal security flaw.

"No research that I'm aware of indicates a Signal vulnerability, there is no CVE and no other details available other than the cryptic copy-paste message," Hammond told us. "At face value it does seem like a strange 'scream test' to see how fast information can travel without validation." ®

Get our [19]Tech Resources



[1] https://twitter.com/signalapp/status/1713789255359619171

[2] https://twitter.com/signalapp/status/1713789255359619171?ref_src=twsrc%5Etfw

[3] https://twitter.com/signalapp/status/1713789257599353084

[4] https://twitter.com/_JohnHammond/status/1713662733462425671

[5] https://www.linkedin.com/posts/misaylor_signal-mobile-app-a-zero-day-exploit-for-activity-7119139278810447872-TFc5/

[6] https://journa.host/@mattblaze@federate.social/111239849679990319

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZS2yh@ZrpKQQIQJiuWbOsgAAAkw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZS2yh@ZrpKQQIQJiuWbOsgAAAkw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZS2yh@ZrpKQQIQJiuWbOsgAAAkw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[10] https://www.theregister.com/2023/09/12/chrome_browser_webp_exploit/

[11] https://github.com/signalapp/Signal-iOS/commit/b3c14576a06c7f4f45435c1424d1da63883b2b41

[12] https://www.theregister.com/2023/09/20/signal_adopts_new_alphabet_jumble/

[13] https://www.theregister.com/2023/09/12/chrome_browser_webp_exploit/

[14] https://www.theregister.com/2023/10/10/october_2023_patch_tuesday/

[15] https://www.theregister.com/2023/10/05/once_again_apple_issues_security/

[16] https://twitter.com/LitMoose/status/1713920503851663486

[17] https://journa.host/@mattblaze@federate.social

[18] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZS2yh@ZrpKQQIQJiuWbOsgAAAkw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[19] https://whitepapers.theregister.com/



“turn off features that you aren't using”?

I am David Jones

Life’s too short to go through all my apps and other software and turn off features that I don’t need. Or think I don’t need.

And, of course, to then go through and fix what I did because I didn’t fully understand the implications of all those changes…

Re: “turn off features that you aren't using”?

Dan 55

I'd think turning off link previews in messaging apps is one of the first things any self-respecting commentard would do to, firstly to stop malware from dodgy spam messages being downloaded, secondly to stop your phone number being confirmed, and thirdly to stop being geolocated from your IP address.

Home is the place where, when you have to go there, they have to take you in.
-- Robert Frost, "The Death of the Hired Man"