Invisibility Bypass in Discord Client
CVE-2026-24332
4.3MEDIUM
What is CVE-2026-24332?
A vulnerability in the Discord Client allows an attacker to infer a user's 'Invisible' status through the WebSocket API. This occurs because the API response includes users marked as 'offline' in the presences array, which can lead to confusion about actual user visibility. Although the UI indicates that users with an 'Invisible' status appear offline, this inconsistency may result in unauthorized access to a user's client state, thus compromising their privacy and security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WebSocket API service 0 <= 2026-01-16
