CVE-2025-5715
A vulnerability was found in Signal App 7.41.4 on Android.
Does this matter?
Lower severity and a low EPSS score (0.29%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was found in Signal App 7.41.4 on Android. It has been declared as problematic. This vulnerability affects unknown code of the component Biometric Authentication Handler. The manipulation leads to missing critical step in authentication. It is possible to launch the attack on the physical device. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
- CVSS 4.0
- 0.3 LOWCVSS:4.0/AV:P/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.29% probability · 22th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-304, CWE-306
- Affected
- signal/signal
- Source
- cna@vuldb.com
References
- https://drive.google.com/file/d/1tI0bC8X8546ActlzGlmSU-AhCdD950y4/view?usp=drivesdkExploit
- https://vuldb.com/?ctiid.311236Permissions Required, VDB Entry
- https://vuldb.com/?id.311236Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.585069Third Party Advisory, VDB Entry
- https://drive.google.com/file/d/1tI0bC8X8546ActlzGlmSU-AhCdD950y4/viewExploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.