Signal
- Known vulnerabilities
- 0
- Still open
- 0
- KEV open
- 0
- Max CVSS (historical)
- —
Cumulative exposure
Low
Aggregates open CVEs (40%) + KEV (30%) + critical shared permissions (15%) + trackers (10%) + OS EOL (5%). Higher score = more exposed.
-
Open CVEs +0/+50
0 open CVEs, max CVSS 0.0, EPSS 0%
-
Active KEVs +0/+35
0 CISA KEVs still open
-
Permissions +0/+10
0 critical shared permission(s)
-
Trackers +0/+8
0 identification/profiling tracker(s)
-
EOL OS +0/+5
Installed OS is end-of-life
Based on permissions only: no CVE data referenced for this app.
Known vulnerabilities (CVE)
No CVE is currently referenced in NVD for this app on its platform.
The absence of CVEs is not a security guarantee — it can also mean nobody has audited or published findings.
Context
Context
Description
Signal is a messaging app with privacy at its core. It is free and easy to use, with strong end-to-end encryption that keeps your communication completely private. • Send texts, voice messages, photos, videos, GIFs, and files for free. Signal uses your phone’s data connection, so you avoid SMS and MMS fees. • Call your friends with crystal-clear encrypted voice and video calls. Group calls supported for up to 50 people. • Stay connected with group chats up to 1,000 people. Control who can post and manage group members with admin permission settings. • Share image, text, and video Stories that disappear after 24 hours. Privacy settings keep you in charge of exactly who can see each Story. • Signal is built for your privacy. We know nothing about you or who you’re talking to. Our open source Signal Protocol means that we can’t read your messages or listen to your calls. Neither can anyone else. No back doors, no data collection, no compromises. • Signal is independent and not for profit; a different kind of tech from a different kind of organization. As a 501c3 nonprofit we are supported by your donations, not by advertisers or investors.
Data collected and shared
Source: App Store · App Privacy · 2 data item(s) declared
Indicative classification based on data sensitivity. "Shared" = transmitted to third parties (publisher-declared).
FAQ
FAQ: Signal
Why are no CVEs listed for Signal?
No CVE is currently referenced in NVD for Signal (org.whispersystems.signal) with a iOS CPE configuration. Either none has been publicly disclosed, or none has been mapped yet. Absence of a CVE is not a security guarantee.
What is the latest known version of Signal?
The most recent version of Signal (org.whispersystems.signal) tracked by Appaloosa Scout is 8.23, published by Signal Messenger, LLC.