Vulnerability · NVD
CVE-2018-3988
MEDIUM 4.7
Signal Messenger for Android 4.24.8 may expose private information when using "disappearing messages." If a user uses the photo feature available in the "attach file" menu, then Signal will leave the picture in its own cache directory, which is available to any application on the system.
Attack vector : Local
No user interaction
Show raw CVSS vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.51%
exploit very unlikely
percentile 40.6%
Tracked apps referencing this CVE
For each app: the affected range, the fixing version, and where the tracked app stands today.
Vulnerable CPE configurations (1)
| Vendor | Product | Platform | Versions | CPE 2.3 URI |
|---|---|---|---|---|
| signal |
private_messenger Android
|
Android | — | cpe:2.3:a:signal:private_messenger:4.24.8:*:*:*:*:android:*:* |