Vulnerability Details CVE-2023-24069
Signal Desktop before 6.2.0 on Windows, Linux, and macOS allows an attacker to obtain potentially sensitive attachments sent in messages from the attachments.noindex directory. Cached attachments are not effectively cleared. In some cases, even after a self-initiated file deletion, an attacker can still recover the file if it was previously replied to in a conversation. (Local filesystem access is needed by the attacker.) NOTE: the vendor disputes the relevance of this finding because the product is not intended to protect against adversaries with this degree of local access.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 16.8%
CVSS Severity
CVSS v3 Score 3.3
Products affected by CVE-2023-24069
-
cpe:2.3:a:signal:signal-desktop:0.1.11
-
cpe:2.3:a:signal:signal-desktop:0.1.12
-
cpe:2.3:a:signal:signal-desktop:0.11.0
-
cpe:2.3:a:signal:signal-desktop:0.11.1
-
cpe:2.3:a:signal:signal-desktop:0.12.0
-
cpe:2.3:a:signal:signal-desktop:0.12.3
-
cpe:2.3:a:signal:signal-desktop:0.12.4
-
cpe:2.3:a:signal:signal-desktop:0.12.5
-
cpe:2.3:a:signal:signal-desktop:0.13.0
-
cpe:2.3:a:signal:signal-desktop:0.14.0
-
cpe:2.3:a:signal:signal-desktop:0.15.0
-
cpe:2.3:a:signal:signal-desktop:0.16.0
-
cpe:2.3:a:signal:signal-desktop:0.16.1
-
cpe:2.3:a:signal:signal-desktop:0.17.0
-
cpe:2.3:a:signal:signal-desktop:0.17.1
-
cpe:2.3:a:signal:signal-desktop:0.18.0
-
cpe:2.3:a:signal:signal-desktop:0.19.0
-
cpe:2.3:a:signal:signal-desktop:0.2.0
-
cpe:2.3:a:signal:signal-desktop:0.2.1
-
cpe:2.3:a:signal:signal-desktop:0.2.2
-
cpe:2.3:a:signal:signal-desktop:0.20.0
-
cpe:2.3:a:signal:signal-desktop:0.21.0
-
cpe:2.3:a:signal:signal-desktop:0.22.0
-
cpe:2.3:a:signal:signal-desktop:0.22.1
-
cpe:2.3:a:signal:signal-desktop:0.22.2
-
cpe:2.3:a:signal:signal-desktop:0.23.0
-
cpe:2.3:a:signal:signal-desktop:0.23.1
-
cpe:2.3:a:signal:signal-desktop:0.23.2
-
cpe:2.3:a:signal:signal-desktop:0.24.1
-
cpe:2.3:a:signal:signal-desktop:0.25.0
-
cpe:2.3:a:signal:signal-desktop:0.25.1
-
cpe:2.3:a:signal:signal-desktop:0.25.2
-
cpe:2.3:a:signal:signal-desktop:0.25.3
-
cpe:2.3:a:signal:signal-desktop:0.25.4
-
cpe:2.3:a:signal:signal-desktop:0.26.0
-
cpe:2.3:a:signal:signal-desktop:0.27.0
-
cpe:2.3:a:signal:signal-desktop:0.28.0
-
cpe:2.3:a:signal:signal-desktop:0.29.0
-
cpe:2.3:a:signal:signal-desktop:0.3.0
-
cpe:2.3:a:signal:signal-desktop:0.3.1
-
cpe:2.3:a:signal:signal-desktop:0.3.2
-
cpe:2.3:a:signal:signal-desktop:0.30.0
-
cpe:2.3:a:signal:signal-desktop:0.31.0
-
cpe:2.3:a:signal:signal-desktop:0.32.0
-
cpe:2.3:a:signal:signal-desktop:0.33.0
-
cpe:2.3:a:signal:signal-desktop:0.34.0
-
cpe:2.3:a:signal:signal-desktop:0.35.0
-
cpe:2.3:a:signal:signal-desktop:0.36.0
-
cpe:2.3:a:signal:signal-desktop:0.36.1
-
cpe:2.3:a:signal:signal-desktop:0.37.0
-
cpe:2.3:a:signal:signal-desktop:0.38.0
-
cpe:2.3:a:signal:signal-desktop:0.38.1
-
cpe:2.3:a:signal:signal-desktop:0.38.2
-
cpe:2.3:a:signal:signal-desktop:0.39.0
-
cpe:2.3:a:signal:signal-desktop:0.39.1
-
cpe:2.3:a:signal:signal-desktop:0.4.0
-
cpe:2.3:a:signal:signal-desktop:0.40.0
-
cpe:2.3:a:signal:signal-desktop:0.41.0
-
cpe:2.3:a:signal:signal-desktop:0.41.1
-
cpe:2.3:a:signal:signal-desktop:0.41.2
-
cpe:2.3:a:signal:signal-desktop:0.41.3
-
cpe:2.3:a:signal:signal-desktop:0.42.0
-
cpe:2.3:a:signal:signal-desktop:0.42.1
-
cpe:2.3:a:signal:signal-desktop:0.42.2
-
cpe:2.3:a:signal:signal-desktop:0.42.3
-
cpe:2.3:a:signal:signal-desktop:0.42.4
-
cpe:2.3:a:signal:signal-desktop:0.42.5
-
cpe:2.3:a:signal:signal-desktop:0.42.6
-
cpe:2.3:a:signal:signal-desktop:0.42.7
-
cpe:2.3:a:signal:signal-desktop:0.43.0
-
cpe:2.3:a:signal:signal-desktop:0.43.1
-
cpe:2.3:a:signal:signal-desktop:0.43.2
-
cpe:2.3:a:signal:signal-desktop:0.43.3
-
cpe:2.3:a:signal:signal-desktop:0.43.4
-
cpe:2.3:a:signal:signal-desktop:0.44.10
-
cpe:2.3:a:signal:signal-desktop:0.44.12
-
cpe:2.3:a:signal:signal-desktop:0.44.13
-
cpe:2.3:a:signal:signal-desktop:0.44.14
-
cpe:2.3:a:signal:signal-desktop:0.44.2
-
cpe:2.3:a:signal:signal-desktop:0.44.3
-
cpe:2.3:a:signal:signal-desktop:0.44.4
-
cpe:2.3:a:signal:signal-desktop:0.44.5
-
cpe:2.3:a:signal:signal-desktop:0.44.6
-
cpe:2.3:a:signal:signal-desktop:0.44.7
-
cpe:2.3:a:signal:signal-desktop:0.44.8
-
cpe:2.3:a:signal:signal-desktop:0.44.9
-
cpe:2.3:a:signal:signal-desktop:0.45.0
-
cpe:2.3:a:signal:signal-desktop:0.46.0
-
cpe:2.3:a:signal:signal-desktop:0.46.1
-
cpe:2.3:a:signal:signal-desktop:0.46.2
-
cpe:2.3:a:signal:signal-desktop:0.46.3
-
cpe:2.3:a:signal:signal-desktop:0.46.4
-
cpe:2.3:a:signal:signal-desktop:0.46.5
-
cpe:2.3:a:signal:signal-desktop:0.46.6
-
cpe:2.3:a:signal:signal-desktop:0.47.0
-
cpe:2.3:a:signal:signal-desktop:0.47.1
-
cpe:2.3:a:signal:signal-desktop:0.47.2
-
cpe:2.3:a:signal:signal-desktop:0.48.0
-
cpe:2.3:a:signal:signal-desktop:0.48.1
-
cpe:2.3:a:signal:signal-desktop:0.5.0
-
cpe:2.3:a:signal:signal-desktop:0.5.1
-
cpe:2.3:a:signal:signal-desktop:0.5.2
-
cpe:2.3:a:signal:signal-desktop:0.6.0
-
cpe:2.3:a:signal:signal-desktop:0.7.0
-
cpe:2.3:a:signal:signal-desktop:0.8.0
-
cpe:2.3:a:signal:signal-desktop:0.9.0
-
cpe:2.3:a:signal:signal-desktop:1.0.24
-
cpe:2.3:a:signal:signal-desktop:1.0.25
-
cpe:2.3:a:signal:signal-desktop:1.0.26
-
cpe:2.3:a:signal:signal-desktop:1.0.27
-
cpe:2.3:a:signal:signal-desktop:1.0.29
-
cpe:2.3:a:signal:signal-desktop:1.0.30
-
cpe:2.3:a:signal:signal-desktop:1.0.31
-
cpe:2.3:a:signal:signal-desktop:1.0.32
-
cpe:2.3:a:signal:signal-desktop:1.0.33
-
cpe:2.3:a:signal:signal-desktop:1.0.34
-
cpe:2.3:a:signal:signal-desktop:1.0.35
-
cpe:2.3:a:signal:signal-desktop:1.0.36
-
cpe:2.3:a:signal:signal-desktop:1.0.37
-
cpe:2.3:a:signal:signal-desktop:1.0.38
-
cpe:2.3:a:signal:signal-desktop:1.0.39
-
cpe:2.3:a:signal:signal-desktop:1.0.40
-
cpe:2.3:a:signal:signal-desktop:1.0.41
-
cpe:2.3:a:signal:signal-desktop:1.1.0
-
cpe:2.3:a:signal:signal-desktop:1.10.0
-
cpe:2.3:a:signal:signal-desktop:1.10.1
-
cpe:2.3:a:signal:signal-desktop:1.11.0
-
cpe:2.3:a:signal:signal-desktop:1.12.0
-
cpe:2.3:a:signal:signal-desktop:1.12.1
-
cpe:2.3:a:signal:signal-desktop:1.13.0
-
cpe:2.3:a:signal:signal-desktop:1.14.0
-
cpe:2.3:a:signal:signal-desktop:1.14.1
-
cpe:2.3:a:signal:signal-desktop:1.14.2
-
cpe:2.3:a:signal:signal-desktop:1.14.3
-
cpe:2.3:a:signal:signal-desktop:1.14.4
-
cpe:2.3:a:signal:signal-desktop:1.15.0
-
cpe:2.3:a:signal:signal-desktop:1.15.1
-
cpe:2.3:a:signal:signal-desktop:1.15.2
-
cpe:2.3:a:signal:signal-desktop:1.15.3
-
cpe:2.3:a:signal:signal-desktop:1.15.4
-
cpe:2.3:a:signal:signal-desktop:1.15.5
-
cpe:2.3:a:signal:signal-desktop:1.16.0
-
cpe:2.3:a:signal:signal-desktop:1.16.1
-
cpe:2.3:a:signal:signal-desktop:1.16.2
-
cpe:2.3:a:signal:signal-desktop:1.16.3
-
cpe:2.3:a:signal:signal-desktop:1.17.0
-
cpe:2.3:a:signal:signal-desktop:1.17.1
-
cpe:2.3:a:signal:signal-desktop:1.17.2
-
cpe:2.3:a:signal:signal-desktop:1.17.3
-
cpe:2.3:a:signal:signal-desktop:1.18.0
-
cpe:2.3:a:signal:signal-desktop:1.18.1
-
cpe:2.3:a:signal:signal-desktop:1.19.0
-
cpe:2.3:a:signal:signal-desktop:1.2.0
-
cpe:2.3:a:signal:signal-desktop:1.20.0
-
cpe:2.3:a:signal:signal-desktop:1.21.0
-
cpe:2.3:a:signal:signal-desktop:1.21.1
-
cpe:2.3:a:signal:signal-desktop:1.21.2
-
cpe:2.3:a:signal:signal-desktop:1.22.0
-
cpe:2.3:a:signal:signal-desktop:1.23.0
-
cpe:2.3:a:signal:signal-desktop:1.23.1
-
cpe:2.3:a:signal:signal-desktop:1.23.2
-
cpe:2.3:a:signal:signal-desktop:1.24.0
-
cpe:2.3:a:signal:signal-desktop:1.24.1
-
cpe:2.3:a:signal:signal-desktop:1.25.0
-
cpe:2.3:a:signal:signal-desktop:1.25.1
-
cpe:2.3:a:signal:signal-desktop:1.25.2
-
cpe:2.3:a:signal:signal-desktop:1.25.3
-
cpe:2.3:a:signal:signal-desktop:1.26.0
-
cpe:2.3:a:signal:signal-desktop:1.26.1
-
cpe:2.3:a:signal:signal-desktop:1.26.2
-
cpe:2.3:a:signal:signal-desktop:1.27.1
-
cpe:2.3:a:signal:signal-desktop:1.27.2
-
cpe:2.3:a:signal:signal-desktop:1.27.3
-
cpe:2.3:a:signal:signal-desktop:1.27.4
-
cpe:2.3:a:signal:signal-desktop:1.28.0
-
cpe:2.3:a:signal:signal-desktop:1.29.0
-
cpe:2.3:a:signal:signal-desktop:1.29.1
-
cpe:2.3:a:signal:signal-desktop:1.29.2
-
cpe:2.3:a:signal:signal-desktop:1.29.3
-
cpe:2.3:a:signal:signal-desktop:1.3.0
-
cpe:2.3:a:signal:signal-desktop:1.30.0
-
cpe:2.3:a:signal:signal-desktop:1.4.0
-
cpe:2.3:a:signal:signal-desktop:1.5.0
-
cpe:2.3:a:signal:signal-desktop:1.5.1
-
cpe:2.3:a:signal:signal-desktop:1.5.2
-
cpe:2.3:a:signal:signal-desktop:1.6.0
-
cpe:2.3:a:signal:signal-desktop:1.6.1
-
cpe:2.3:a:signal:signal-desktop:1.7.0
-
cpe:2.3:a:signal:signal-desktop:1.7.1
-
cpe:2.3:a:signal:signal-desktop:1.8.0
-
cpe:2.3:a:signal:signal-desktop:1.9.0
-
cpe:2.3:a:signal:signal-desktop:6.2.0
-
-
cpe:2.3:o:linux:linux_kernel:-
-
cpe:2.3:o:microsoft:windows:-