#VU49847 Insufficient verification of data authenticity in Signal
Published: January 20, 2021
Signal
signal.org
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to the way the mobile application implements WebRTC features for voice and video communications. A remote attacker can send specially crafted SDP messages to the affected device while the victim is trying to make a voice or video call and intercept video and audio fragments from the victim's phone before the call is accepted by the callee.