In response to widespread rumours that a zero-day vulnerability was compromising the Signal messaging platform, the app conducted its own investigation and declared there was no concrete evidence to support the existence of the alleged vulnerability.
The alleged zero-day exploit was rumoured to give threat actors access to your full device. The rumours circulated over the weekend, and suggested that the exploit was related to the ‘Generate Link Previews’ feature.
Multiple reports about the flaw surfaced on X and Reddit, prompting Signal to post a release this morning on X, saying: “PSA: we have seen the vague viral reports alleging a Signal 0-day vulnerability. After responsible investigation we have no evidence that suggests this vulnerability is real nor has any additional info been shared via our official reporting channels.”
Another leading claim about the alleged zero-day was that an unnamed source within the United States Government had acknowledged its existence. To debunk this, Signal spoke with people across the US government, and found “those we spoke to have no info suggesting this is a valid claim.”
While Signal has officially stated that they have not found any concrete evidence of a new zero-day vulnerability, they encourage individuals with genuine and verified information to contact their security team. As the investigation remains ongoing, the recommended course of action for users is to temporarily disable the ‘Generate Link Previews’ feature until the matter is conclusively resolved, ensuring the security of their Signal communications.
Recommended
- Zero-day Vulnerability Found in iOS: Update Your iPhone Now
- Apple Patches Three Zero-Day Vulnerabilities
- LinkedIn Hacking Campaign Illustrates Rise in Zero-Day Exploits
A zero-day vulnerability is a bug in a system that has been discovered but not yet patched. This kind of vulnerability is of high risk to users because cybercriminals usually rush to exploit it while it’s still exposed.
These vulnerabilities are all too common, and growing in frequency. According to Project Zero, there have been around 50 zero-days discovered among major software vendors so far in 2023, more than all of 2022 already.





