Signal flaws allowed rogue servers to decrypt users’ contact queries
Security researchers at V12 discovered two critical vulnerabilities in Signal’s Contact Discovery Service that could allow a malicious server operator to escape the protections of its Intel SGX enclave. The flaws enabled arbitrary reading of protected enclave memory and, in the more severe case, code execution inside the trusted environment. V12 researcher Nihal disclosed the … The post Signal flaws allowed rogue servers to decrypt users’ contact queries appeared first on CyberInsider.
A vulnerability in Signal's Contact Discovery Service allowed a malicious server operator to decrypt users' contact queries, compromising the privacy of Signal users. The vulnerabilities were exploited by a researcher using real Intel SGX hardware.
Read the full article
This is a curated summary. The complete article is available at Cyber Insider.
