URGENT SIGNAL ZERO DAY

Disable generate link preview in signal settings under chats. https://video.nostr.build/a8add5e7937bcde3616b2be969aed1e41a5df9452e5122c06fbe6ebc53de7cd3.mov

Reply to this note

Please Login to reply.

Discussion

🙏🙏

Looks like I already had that disabled. nostr:npub1e2rd2k45ym2jmctnysfadxumrvrr57vqj69ck6trt2y62c40r0kqs9lx8t tagging you for awareness.

Thanks!

Any more info?

Dunno if it’s weaponized but it’s there. Best to just disable the setting.

Thank You!

Mine was already off. Is this enabled by default normally?

On idea

switch to keet.io

I don't use Signal, but out of interest, what is this good for ?

Encrypted end to end messaging.

Link previews seem like a bad idea for a private messenger in general.

Thank you!

Not sure what I'm supposed to take away from your post. 😬

Is this confirming that actually there are vulnerabilities? I cannot open the github links without an account.

They were using a library with a vulnerability in it. If you updated signal recently. You're fine. Or disable the link preview and you're fine.

CVE was a Critical vulnerability for libwebp. Signal iOS and Android use libwebp.

Ah okay, interesting. Thanks.

Is there context to this ? Article, forum post link ?