signalapp / Signal-Desktop

A private messenger for Windows, macOS, and Linux.
https://signal.org/download
GNU Affero General Public License v3.0
14.16k stars 2.57k forks source link

data breach when editing messages in a group #6880

Closed RES-1 closed 1 month ago

RES-1 commented 1 month ago

Using a supported version?

Overall summary

When a message is edited in a group, group members who were not yet members of the group at the time the message was originally created also receive the message.

Steps to reproduce

Expected result

The edited message will not be displayed to the new group member.

Actual result

The edited message is displayed to the new group member.

Screenshots

No response

Signal version

7.9.0

Operating system

GNU/Linux/Fedora/KDE

Version of Signal on your phone

7.6.2

Link to debug log

No response

ayumi-signal commented 1 month ago

Hi, thanks for the report. It's not our intention that people can see messages they weren't sent originally, so we'd like to find out what's going on. We tried to reproduce but weren't able to. Could you please provide more info:

RES-1 commented 1 month ago

I have now created a test environment for this myself. It was a misjudgment that the new member would see the changed message. I apologize for the incorrect error message. The error arose because the changed message indicated in the informations that it was sent to the new member. However, this is just a “cosmetic flaw”.