Exploitation Summary
CVE-2025-47729 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added May 12, 2025.
Description
The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is different functionality than described in the TeleMessage "End-to-End encryption from the mobile phone through to the corporate archive" documentation, as exploited in the wild in May 2025.
References (4)
Core 4
Core References
Press/Media Coverage
https://arstechnica.com/security/2025/05/signal-clone-used-by-trump-official-stops-operations-after-report-it-was-hacked/
Press/Media Coverage
https://news.ycombinator.com/item?id=43909220
Press/Media Coverage
https://www.theregister.com/2025/05/05/telemessage_investigating/
US Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-47729
Scores
CVSS v3
1.9
EPSS
0.0415
EPSS Percentile
89.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
active
Automatable
no
Technical Impact
partial
Details
CISA KEV
2025-05-12
VulnCheck KEV
2025-05-08
ENISA EUVD
EUVD-2025-14003
CWE
CWE-912
Status
published
Products (1)
telemessage/text_message_archiver
< 2025-05-05
Published
May 08, 2025
KEV Added
May 12, 2025
Tracked Since
Feb 18, 2026