URI Spoofing Vulnerability in Signal App for iOS
CVE-2022-28345
What is CVE-2022-28345?
The Signal app for iOS versions earlier than 5.34 is susceptible to URI spoofing through the exploitation of RTLO (Right-to-Left Override) injection. This vulnerability allows remote attackers to craft deceptive links that appear to redirect users to a trusted website but instead lead to malicious destinations. By leveraging a specific encoding method with non-breaking spaces at the beginning of URLs, attackers can disguise harmful URLs in a way that seems legitimate, employing subdomains that appear reversed. This poses a significant risk for users, as it enables social engineering tactics that could compromise sensitive information.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
