Later archive addition
Accidentally finding RCE in Signal Desktop via HTML injection in quoted replies
A quoted-reply rendering flaw in Signal Desktop allowed crafted HTML from a message to be reinserted without adequate sanitization. In the Electron application, the resulting HTML injection could reach privileged behavior and be chained into remote code execution when a victim viewed the conversation.
Record
- Researcher
- @IAmMandatory
- Published by
- The Hacker Blog
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of @IAmMandatory, first published at the original source. Preserved copies are kept so the citation survives its host.