CVE-2019-17191
HIGHSignal Private Messenger < 4.47.7 - Unauthenticated Call Forcing via Connect Message
Title source: llmDescription
The Signal Private Messenger application before 4.47.7 for Android allows a caller to force a call to be answered, without callee user interaction, via a connect message. The existence of the call is noticeable to the callee; however, the audio channel may be open before the callee can block eavesdropping.
References (3)
Core 3
Core References
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://news.ycombinator.com/item?id=21161432
Third Party Advisory x_refsource_misc
https://twitter.com/moxie/status/1180261210341511168
Exploit, Third Party Advisory x_refsource_misc
https://bugs.chromium.org/p/project-zero/issues/detail?id=1943
Scores
CVSS v3
7.5
EPSS
0.0180
EPSS Percentile
75.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-863
Status
published
Products (1)
signal/private_messenger
< 4.47.7
Published
Oct 05, 2019
Tracked Since
Feb 18, 2026