Open Whisper Signal (aka Signal-Desktop) through 1.23.1 and the Signal Private Messenger application through 4.35.3 for Android are vulnerable to an IDN homograph attack when displaying messages containing URLs. This occurs because the application produces a clickable link even if (for example) Latin and Cyrillic characters exist in the same domain name, and the available font has an identical representation of characters from different alphabets.
{
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "4.35.3"
}
],
"source": "CPE_RANGE",
"cpe": "cpe:2.3:a:signal:private_messenger:*:*:*:*:*:android:*:*"
}
{
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "1.23.1"
}
],
"source": "CPE_RANGE",
"cpe": "cpe:2.3:a:signal:signal-desktop:*:*:*:*:*:*:*:*"
}