Web Hack List

Later archive addition

Accidentally finding RCE in Signal Desktop via HTML injection in quoted replies

A quoted-reply rendering flaw in Signal Desktop allowed crafted HTML from a message to be reinserted without adequate sanitization. In the Electron application, the resulting HTML injection could reach privileged behavior and be chained into remote code execution when a victim viewed the conversation.

Record

Researcher
@IAmMandatory
Published by
The Hacker Blog

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of @IAmMandatory, first published at the original source. Preserved copies are kept so the citation survives its host.