CVE-2018-3988
Signal Messenger for Android 4.24.8 may expose private information when using "disappearing messages." If a user uses the photo feature available in the "attach file" menu, then Signal will leave the picture in its own cache directory, which is…
Does this matter?
Lower severity and a low EPSS score (0.53%). Track it; it rarely justifies an emergency change on its own.
Description
Signal Messenger for Android 4.24.8 may expose private information when using "disappearing messages." If a user uses the photo feature available in the "attach file" menu, then Signal will leave the picture in its own cache directory, which is available to any application on the system.
- CVSS 3.1
- 4.7 MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.53% probability · 43th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- signal/private messenger
- Source
- talos-cna@cisco.com
References
- http://www.securityfocus.com/bid/106207Broken Link, Third Party Advisory, VDB Entry
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0656Exploit, Third Party Advisory
- http://www.securityfocus.com/bid/106207Broken Link, Third Party Advisory, VDB Entry
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0656Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.