The Signal Messenger app is investigating rumors that circulated online over the weekend about a zero-day vulnerability related to the “Create Link Previews” feature, stating that there is no evidence that this vulnerability is real.
See also: Trojanized Signal and Telegram apps infected users with BadBazaar spyware

This statement follows multiple sources speaking to BleepingComputer and Twittersaying that a new zero-day vulnerability allows full disclosure of devices. After reaching out to Signal about the zero-day vulnerability, they announced via X that they have investigated the rumors and found no evidence of the flaw.
“Announcement: We have seen the vague reports that have gone viral, claiming the existence of a ZERO-DAY vulnerability in Signal,” reads a message on X.
“After a responsible investigation, we have no findings indicating the existence of this vulnerability, nor has additional information been shared through our official reporting channels.“
“We also checked with people in US government agencies, since the copy-paste report cited the US government as a source. Those we spoke to have no information to suggest that this is an authoritative statement.“
Citing US government, news of the alleged zero-day spread quickly across the internet and cybersecurity community on Saturday afternoon. These anonymous USG sources said the vulnerability could be addressed by disabling the 'Create link previews' setting in Signal.
See also: SafeChat: Fake app steals Signal and WhatsApp data

However, the validity of these statements could not be confirmed, even though we heard them from many people claiming exactly the same thing and from the same sources.
Παρότι η Signal έχει δηλώσει ότι δεν έχει αποδείξεις για ένα νέο zero-day, ζητάει ακόμα από όσους έχουν νέες και “πραγματικές” πληροφορίες να επικοινωνήσουν με την ομάδα ασφαλείας της.
As the research on the vulnerability continues, even the mitigation simply involves disabling the Link Preview feature; users may want to disable this setting for the time being, until it is fully confirmed that it is not genuine.
A zero-day bug is a type of vulnerability that is unknown to the software manufacturer or vendor. This term comes from the fact that the software manufacturer does not have a day to compile and distribute a fix before malicious users begin exploiting the vulnerability.
See also: Microsoft Cyber Signals: Vulnerabilities in critical infrastructure
How widespread is the problem?
Zero-day bugs are not uncommon. Vulnerabilities that have not been detected or patched by software vendors are often found and can be exploited in both consumer operating systems and business applications . Discovering and fixing zero-day bugs is essential to maintaining the security of software. Without timely detection and patching, malicious users can exploit these vulnerabilities to gain access to confidential information, cause damage to systems, or disrupt critical services.
Possible consequences of a zero-day bug
Zero-day bugs are particularly serious threats to the security of digital systems. The existence of such a flaw means that attackers have the ability to exploit the system before the responsible parties detect and fix it. The problem is even more urgent, given that zero-day bugs can remain unnoticed for a long period of time.
Exploitation of a zero-day bug can lead to multiple security breaches. Applications or systems affected by these flaws can experience:
- Personal data leak: If a system that manages sensitive data is affected, users' personal data may be leaked.
- Gaining Uncontrolled Access: Hackers can gain access to computer systems and control operations.
- Serious financial losses: Exploiting these flaws can lead to significant financial losses, both from information leakage and from system restoration actions.
Even though zero-day bugs pose a serious risk, a substantive response by information security professionals can reduce the likelihood of a breach.
Source: bleepingcomputer
