Post #1299939
2026-04-14 15:35 UTC
My colleague @jaras recently found that a an Android app with zero permissions could exfiltrate all decrypted Signal attachments (affecting the Android APKs downloaded directly from signal.org). Look at the attack scenario our GitHub Security Lab Taskflow Agent produced. This is what AI-assisted security research looks like:
https://securitylab.github.com/advisories/GHSL-2026-102_Android_SignalApp/
Replies (1)
-
@ulldma@infosec.exchange 2026-04-14 15:35
This is not even the first Signal issue Jaro found with the help of our Taskflow Agent: have a look at our advisories page to see the other ones: https://securitylab.github.com/advisories/ Also noted on Signal’s Security Acknowledgments page: https://signal.org/security/