Global Feed Post Login
Replying to Avatar Techlore

A researcher has shown how they zero-click exposed user's locations of most messaging apps, including Signal and Twitter/X. Here's what you need to know ๐Ÿงต

First, this issue exploited Cloudflare's CDN. An attacker only needs to send an image in order to obtain a very coarse location based on delivery timing of the message. This requires no involvement from the victim, so it's 0-click. Cloudflare has since fixed the issue.

Avatar
freemymind ๐Ÿ‡จ๐Ÿ‡ญ 11mo ago

Is there any article to this issue? And what precautions to take?

Reply to this note

Please Login to reply.

Discussion

No replies yet.