CVE-2023-24069: Infoleak
DISPUTED Signal Desktop before 6.2.0 on Windows, Linux, and macOS allows an attacker to obtain potentially sensitive attachments sent in messages from the attachments.noindex directory. Cached attachments are not effectively cleared. In some cases, even after a self-initiated file deletion, an attacker can still recover the file if it was previously replied to in a conversation. (Local filesystem access is needed by the attacker.) NOTE: the vendor disputes the relevance of this finding because the product is not intended to protect against adversaries with this degree of local access.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-24069.
What is the severity of CVE-2023-24069?
The severity of CVE-2023-24069 is low (3.3).
Which software versions are affected by CVE-2023-24069?
Signal Desktop versions before 6.2.0 on Windows, Linux, and macOS are affected.
How can an attacker exploit CVE-2023-24069?
An attacker can exploit CVE-2023-24069 to obtain potentially sensitive attachments sent in messages from the attachments.noindex directory.
Is there a fix available for CVE-2023-24069?
Yes, updating Signal Desktop to version 6.2.0 or later will fix CVE-2023-24069.