Signal's vulnerability profile centers on its desktop and mobile messaging application, a widely used encrypted communications platform with a globally distributed user base. The recurring weakness classes reflect application-layer risks in client-side message handling and web-view rendering, including sensitive information exposure, cross-site scripting, and input-injection issues. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Signal over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-17192CRITICAL The WebRTC component in the Signal Private Messenger application through 4.47.7 for Android processes videoconferencing RTP packets before a callee chooses to answer a call, which | Oct 5, 2019 | 9.8 | 31 | NO | NO |
CVE-2018-16132HIGH The image rendering component (createGenericPreview) of the Open Whisper Signal app through 2.29.0 for iOS fails to check for unreasonably large images before manipulating received | Aug 29, 2018 | 8.6 | 27 | NO | NO |
CVE-2023-24068HIGH Signal Desktop before 6.2.0 on Windows, Linux, and macOS allows an attacker to modify conversation attachments within the attachments.noindex directory. Client mechanisms fail to v | Jan 23, 2023 | 7.8 | 26 | NO | NO |
CVE-2022-28345HIGH The Signal app before 5.34 for iOS allows URI spoofing via RTLO injection. It incorrectly renders RTLO encoded URLs beginning with a non-breaking space, when there is a hash charac | Apr 15, 2022 | 7.5 | 25 | NO | NO |
CVE-2019-17191HIGH The Signal Private Messenger application before 4.47.7 for Android allows a caller to force a call to be answered, without callee user interaction, via a connect message. The exist | Oct 5, 2019 | 7.5 | 25 | NO | NO |
CVE-2019-19954HIGH Signal Desktop before 1.29.1 on Windows allows local users to gain privileges by creating a Trojan horse %SYSTEMDRIVE%\node_modules\.bin\wmic.exe file. | Dec 24, 2019 | 7.3 | 23 | NO | NO |
CVE-2018-9840MEDIUM The Open Whisper Signal app before 2.23.2 for iOS allows physically proximate attackers to bypass the screen locker feature via certain rapid sequences of actions that include app | Apr 10, 2018 | 6.8 | 23 | NO | NO |
CVE-2018-11101MEDIUM Open Whisper Signal (aka Signal-Desktop) through 1.10.1 allows XSS via a resource location specified in an attribute of a SCRIPT, IFRAME, or IMG element, leading to JavaScript exec | May 17, 2018 | 6.1 | 22 | NO | NO |
CVE-2018-10994MEDIUM js/views/message_view.js in Open Whisper Signal (aka Signal-Desktop) before 1.10.1 allows XSS via a URL. | May 14, 2018 | 6.1 | 22 | NO | NO |
CVE-2025-5715MEDIUM A vulnerability was found in Signal App 7.41.4 on Android. It has been declared as problematic. This vulnerability affects unknown code of the component Biometric Authentication Ha | Jun 6, 2025 | 6.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Signal.
Media articles that mention a CVE ID that affects a product developed by Signal — matched by CVE ID, not by vendor name.