CVE-2022-28345
HIGH 7.5EPSS 2.5%
The Signal app before 5.34 for iOS allows URI spoofing via RTLO injection. It incorrectly renders RTLO encoded URLs beginning with a non-breaking space, when there is a hash character in the URL. This technique allows a remote unauthenticated attacker to send legitimate looking links, appearing to be any website URL, by abusing the non-http/non-https automatic rendering of URLs. An attacker can spoof, for example, example.com, and masquerade any URL with a malicious destination. An attacker requires a subdomain such as gepj, txt, fdp, or xcod, which would appear backwards as jpeg, txt, pdf, and docx respectively.
- CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N - CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N - EPSS
- 2.46% chance of exploitation in the next 30 days, 83th percentile
- Published
- 2022-04-15
- Updated
- 2024-08-03