CVE-2022-28345
The Signal app before 5.34 for iOS allows URI spoofing via RTLO injection.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.49%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Signal app before 5.34 for iOS allows URI spoofing via RTLO injection. It incorrectly renders RTLO encoded URLs beginning with a non-breaking space, when there is a hash character in the URL. This technique allows a remote unauthenticated attacker to send legitimate looking links, appearing to be any website URL, by abusing the non-http/non-https automatic rendering of URLs. An attacker can spoof, for example, example.com, and masquerade any URL with a malicious destination. An attacker requires a subdomain such as gepj, txt, fdp, or xcod, which would appear backwards as jpeg, txt, pdf, and docx respectively.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 2.49% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74
- Affected
- signal/signal
- Source
- cve@mitre.org
References
- https://blog.malwarebytes.com/social-engineering/2022/03/uri-spoofing-flaw-could-phish-whatsapp-signal-instagram-and-imessage-users/Third Party Advisory
- https://github.com/sickcodes/security/blob/master/advisories/SICK-2022-42.mdExploit, Patch, Third Party Advisory
- https://github.com/zadewg/RIUSThird Party Advisory
- https://sick.codes/sick-2022-42Exploit, Patch, Third Party Advisory
- https://blog.malwarebytes.com/social-engineering/2022/03/uri-spoofing-flaw-could-phish-whatsapp-signal-instagram-and-imessage-users/Third Party Advisory
- https://github.com/sickcodes/security/blob/master/advisories/SICK-2022-42.mdExploit, Patch, Third Party Advisory
- https://github.com/zadewg/RIUSThird Party Advisory
- https://sick.codes/sick-2022-42Exploit, Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.