CVE-2019-17191 describes a high-severity vulnerability in Signal Private Messenger for Android versions prior to 4.47.7, allowing an attacker to force a call to be answered without user interaction. This flaw could lead to unauthorized audio eavesdropping, as the audio channel might open before the callee can react, despite the call's presence being noticeable. With a CVSS score of 7.5 (HIGH), the attack requires no user interaction and has low complexity, posing a significant privacy risk. While there is no evidence of active exploitation or public exploit code, the vulnerability has garnered some community discussion and media coverage, indicating its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.47.7CPE matchmatch criteria | cpe:2.3:a:signal:private_messenger:*:*:*:*:*:android:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.