I have:
Groups can be compromised if group id and one member is known, as documented here (page 8 and following)
See link from Bug description
This should be fixed by checking whether a user is part of a group before updating it.
Page 18:
Open WhisperSystems is currently developing a new group management system with advanced administrative features so that they decided not apply our fix.
GitHub Issue Cleanup:
See #7598 for more information.
Most helpful comment
Page 18: