2 ms·
Full remote code execution in signal desktop via an node context enabled and an XSS in a react application, rendering user messages with __dangerouslySetInnerHT
by cbxyp 5y ago
Full remote code execution in signal desktop via an node context enabled and an XSS in a react application, rendering user messages with __dangerouslySetInnerHTML. A similar XSS in the webview on mobile signal allowed at the very least, compromising all of the contacts and messages of the user.
I wouldn't take anything that Signal developers/founders say about their product or others' products security seriously.