CVE-2018-3988: Infoleak
Signal Messenger for Android 4.24.8 may expose private information when using "disappearing messages." If a user uses the photo feature available in the "attach file" menu, then Signal will leave the picture in its own cache directory, which is available to any application on the system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-3988?
CVE-2018-3988 is a vulnerability in Signal Messenger for Android 4.24.8 that may expose private information when using disappearing messages.
How does CVE-2018-3988 affect Signal Messenger for Android 4.24.8?
CVE-2018-3988 affects Signal Messenger for Android 4.24.8 by leaving pictures in its cache directory, which can be accessed by any application on the system.
What is the severity of CVE-2018-3988?
CVE-2018-3988 has a severity value of 4.7 (medium).
How can I fix the CVE-2018-3988 vulnerability?
To fix the CVE-2018-3988 vulnerability, it is recommended to update Signal Messenger for Android to a version that addresses this issue.
Are there any references regarding CVE-2018-3988?
Yes, you can find more information about CVE-2018-3988 at the following references: - [SecurityFocus link](http://www.securityfocus.com/bid/106207) - [Talos Intelligence link](https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0656)