GHSL-2026-112: _GHSL-2026-113: Cross-thread authorization flaws allow unauthorized pin changes and poll votes in Signal for iOS
Published Sep 21, 2026
·Updated
Any registered Signal user can unpin a message in any group on the recipient's device, corrupt that group's pin record, or cast a vote in a poll in a group they are not a member of.
Affected Software
1 affected component
Signal Signal for iOS
Event History
Sep 21, 2026
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
Description
Frequently Asked Questions
1
Who can exploit these issues?
Any registered Signal user can exploit them. The affected actions can target groups that the attacker is not a member of.
2
What unauthorized actions are possible?
An attacker can unpin a message in any group on the recipient's device, corrupt that group's pin record, or cast a poll vote in a group they do not belong to.