CVE-2025-24903

CVSS 3.1 Score 8.5 of 10 (high)

Details

Published Feb 13, 2025
CWE ID 345

Summary

CVE-2025-24903 is a vulnerability affecting the libsignal-service-rs library, a Rust implementation of the libsignal-service-java library used for communication with Signal servers. Before commitment 82d70f6720e762898f34ae76b0894b0297d9b2f8, any contact could forge a sync message, allowing impersonation of another device belonging to the local user. The origin of sync messages was not verified, leading to this security weakness. A patched version of the library is available after this commitment. However, an additional `was_encrypted` field has been introduced in the `Metadata` struct, which breaks the API but should be easily resolvable. At present, no workarounds have been identified for this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share