First published: Tue Apr 10 2018(Updated: )
The Open Whisper Signal app before 2.23.2 for iOS allows physically proximate attackers to bypass the screen locker feature via certain rapid sequences of actions that include app opening, clicking on cancel, and using the home button.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Signal Signal | <2.23.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-9840 is a vulnerability in the Open Whisper Signal app before version 2.23.2 for iOS that allows physically proximate attackers to bypass the screen locker feature.
An attacker can exploit CVE-2018-9840 by performing certain rapid sequences of actions, including app opening, clicking on cancel, and using the home button.
The severity of CVE-2018-9840 is medium, with a severity value of 6.8.
The Open Whisper Signal app before version 2.23.2 for iOS is affected by CVE-2018-9840.
Yes, the fix for CVE-2018-9840 is available in version 2.23.2 of the Open Whisper Signal app for iOS.