Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Signal

First CVE: Apr 10, 2018Active for: 8 yearsTotal CVEs: 15
19.0
VTI Score
Low

Signal's vulnerability profile centers on its desktop and mobile messaging application, a widely used encrypted communications platform with a globally distributed user base. The recurring weakness classes reflect application-layer risks in client-side message handling and web-view rendering, including sensitive information exposure, cross-site scripting, and input-injection issues. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 41% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Signal over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 10, 2018
8 years ago
Most Recent CVE
Jun 6, 2025
413 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-17192CRITICAL
The WebRTC component in the Signal Private Messenger application through 4.47.7 for Android processes videoconferencing RTP packets before a callee chooses to answer a call, which
Oct 5, 20199.831NONO
CVE-2018-16132HIGH
The image rendering component (createGenericPreview) of the Open Whisper Signal app through 2.29.0 for iOS fails to check for unreasonably large images before manipulating received
Aug 29, 20188.627NONO
CVE-2023-24068HIGH
Signal Desktop before 6.2.0 on Windows, Linux, and macOS allows an attacker to modify conversation attachments within the attachments.noindex directory. Client mechanisms fail to v
Jan 23, 20237.826NONO
CVE-2022-28345HIGH
The Signal app before 5.34 for iOS allows URI spoofing via RTLO injection. It incorrectly renders RTLO encoded URLs beginning with a non-breaking space, when there is a hash charac
Apr 15, 20227.525NONO
CVE-2019-17191HIGH
The Signal Private Messenger application before 4.47.7 for Android allows a caller to force a call to be answered, without callee user interaction, via a connect message. The exist
Oct 5, 20197.525NONO
CVE-2019-19954HIGH
Signal Desktop before 1.29.1 on Windows allows local users to gain privileges by creating a Trojan horse %SYSTEMDRIVE%\node_modules\.bin\wmic.exe file.
Dec 24, 20197.323NONO
CVE-2018-9840MEDIUM
The Open Whisper Signal app before 2.23.2 for iOS allows physically proximate attackers to bypass the screen locker feature via certain rapid sequences of actions that include app
Apr 10, 20186.823NONO
CVE-2018-11101MEDIUM
Open Whisper Signal (aka Signal-Desktop) through 1.10.1 allows XSS via a resource location specified in an attribute of a SCRIPT, IFRAME, or IMG element, leading to JavaScript exec
May 17, 20186.122NONO
CVE-2018-10994MEDIUM
js/views/message_view.js in Open Whisper Signal (aka Signal-Desktop) before 1.10.1 allows XSS via a URL.
May 14, 20186.122NONO
CVE-2025-5715MEDIUM
A vulnerability was found in Signal App 7.41.4 on Android. It has been declared as problematic. This vulnerability affects unknown code of the component Biometric Authentication Ha
Jun 6, 20256.420NONO
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
53%
33%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local5 (33.3%)
Network8 (53.3%)
Unknown0 (0.0%)
Physical2 (13.3%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (86.7%)
High2 (13.3%)
Unknown0 (0.0%)
User Interaction
None11 (73.3%)
Unknown0 (0.0%)
Required4 (26.7%)
Privileges Required
Low4 (26.7%)
High0 (0.0%)
None11 (73.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Signal.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Signal — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Signal's Products

View all 4 CNAs →

Top CWEs