Application security Signal contact discovery service vulnerabilities allowed enclave escape August 28, 2026 Share By SC Staff (Adobe Stock) Based on information from Cyber Insider, security researchers have discovered critical vulnerabilities in Signal’s Contact Discovery Service that could allow a malicious server operator to bypass protections offered by its Intel SGX enclave. Researchers at V12 identified two flaws in Signal's Contact Discovery Service (CDSI), which is designed to help users find contacts on Signal without revealing their address book to the service. The vulnerabilities, found in the Intel SGX enclave used for sensitive processing, could permit arbitrary reading of protected memory and, in a more severe case, code execution within the trusted environment. The first flaw involved a race condition allowing a malicious host to read enclave memory, potentially enabling impersonation and decryption of queries. The second vulnerability, a time-of-check-to-time-of-use flaw, could allow an attacker to gain control over the enclave's CPU and execute arbitrary code. V12 developed working exploits and tested them on hardware matching Signal's production environment. Signal has since patched both vulnerabilities by enforcing single workers per shard and combining validity checks into atomic operations. As the fixes were applied server-side, users do not need to take action beyond keeping their Signal app updated. Source: Cyber Insider SC Staff Related AI/ML From browser control to agent control: Governing the new AI workforce Paul Wagenseil August 27, 2026 Oversight of AI agents requires a new approach that looks at the modern endpoint from the inside out. Application security How to Build an Injection and Data Handling Security Program SC Media Editorial Intelligence, reviewed by Antonio Ball August 27, 2026 AI/ML Shadow AI surges as 80% of employee AI tools evade IT oversight Laura French August 27, 2026 Reco’s The State of Agent Security 2026 report highlights shadow AI, MCP risks and AI vulnerability trends. Related Events Cybercast Bridging the Gap from CISO-Developed Tools to Black Hat Hype: What AI Security Leaders Should Watch Next On-Demand Event Cybercast Protecting Application User Data for Better Privacy, Governance, and Compliance On-Demand Event Cybercast The Next Evolution of Application Security: AI- Accelerated DevSecOps On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Banner Browser Cache Cramming Common Gateway Interface (CGI) Client Cookie DLL Injection Dynamic Link Library You can skip this ad in 5 seconds