Information disclosure in Signal Private Messenger for iOS and Signal Private Messenger for Android - CVE-2020-5753

 

Information disclosure in Signal Private Messenger for iOS and Signal Private Messenger for Android - CVE-2020-5753

Published: May 21, 2020


Vulnerability identifier: #VU28172
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-5753
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to application discloses currently used DNS server to arbitrary user from non-contact list. The issue is related to how WebRTC processes ICE Candidates, which takes place before a user decides to answer an incoming Signal call. A remote attacker can gain access to victim's current DNS server IP address and based on this data uncover victim's geographical location.


Affected software

Signal Private Messenger for iOS
Signal Private Messenger for Android

How to mitigate CVE-2020-5753

Install updates from vendor's website.


External References

Related Security Bulletins