GHSL-2026-113: GHSL-2026-112_GHSL-2026-113: Cross-thread authorization flaws allow unauthorized pin changes and poll votes in Signal for iOS
Published Sep 21, 2026
·Updated
Any registered Signal user can unpin a message in any group on the recipient's device, corrupt that group's pin record, or cast a vote in a poll in a group they are not a member of.
Affected Software
1 affected component
Signal Signal for iOS
Event History
Sep 21, 2026
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
Description
Frequently Asked Questions
1
Does an attacker need to belong to the targeted group?
No. A registered Signal user can cast a poll vote in a group they are not a member of.
2
What access does an attacker need to exploit the issue?
The attacker needs to be a registered Signal user. The available information does not state any further prerequisite access.
3
Which data or actions can be affected on a recipient's device?
An attacker can unpin a message in any group on the recipient's device and corrupt that group's pin record. They can also cast a poll vote without being a member of the affected group.