CVE-2019-17191: High severity signal private messenger vulnerability
The Signal Private Messenger application before 4.47.7 for Android allows a caller to force a call to be answered, without callee user interaction, via a connect message. The existence of the call is noticeable to the callee; however, the audio channel may be open before the callee can block eavesdropping.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-17191?
CVE-2019-17191 is a vulnerability that allows a caller to force a call to be answered in the Signal Private Messenger application before version 4.47.7 for Android.
How severe is CVE-2019-17191?
CVE-2019-17191 is considered high severity with a CVSS score of 7.5.
Which version of Signal Private Messenger for Android is affected by CVE-2019-17191?
The vulnerability affects Signal Private Messenger for Android versions up to but not including 4.47.7.
How can I exploit CVE-2019-17191?
We do not provide information or support for exploiting vulnerabilities. CVE-2019-17191 is a vulnerability that should be addressed and fixed.
How do I fix CVE-2019-17191?
To fix CVE-2019-17191, update Signal Private Messenger for Android to version 4.47.7 or later.