The popular encrypted messaging app Signal has patched a critical flaw in its Android app that could have allowed hackers to answer calls on your behalf. The worst part is that you didn't have to do anything to give the malicious users access

Google 's Project Zero team , which uncovered the bug on September 28, said it only affects audio calls, as the video option must be manually enabled for all incoming calls.
Signal has fixed the issue in the latest app update (version 4.47.7).
“Using a modified client, it is possible to send the “connect” message to a calling device when an incoming call is in progress, but has not been accepted by the user. This causes the call to be answered, even though the user has not interacted with the device,” notes Natalie Silvanovich of Project Zero.

The eavesdropping bug would have been a problem in the iOS version of Signal if there wasn't a UI bug that prevented the call from completing. Currently, the flaw cannot be exploited on iOS.
The bug is also similar to a major flaw in FaceTime that was revealed this year, which allowed a remote attacker to hear another person's voice even before they answered your call.
If you use Signal, you need to update your app immediately!
