CVE-2018-9840 describes a bypass vulnerability in the Open Whisper Signal app for iOS, specifically versions prior to 2.23.2. This medium-severity flaw (CVSS 6.8) allows a physically proximate attacker to bypass the screen locker feature through a rapid sequence of actions involving app opening, canceling, and using the home button. While there is no known active exploitation, public exploit code, or Metasploit/Nuclei modules, the vulnerability has garnered some community discussion, with one mention on Reddit.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.23.2CPE matchmatch criteria | cpe:2.3:a:signal:signal:*:*:*:*:*:iphone_os:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.