Signal-android: Private contacts are visible in the direct share menu.

Created on 8 Jun 2020  路  2Comments  路  Source: signalapp/Signal-Android


Bug description

Evidence of communication with private contacts (possibly just phone number of no system contact exists) are visible in the direct share menu. This violates privacy and security of the device.

Steps to reproduce

  • send a message to a private contact with signal.
  • try to share something from another program

Actual result: Describe here what happens after you run the steps above (i.e. the buggy behaviour)

Private contacts are visible in the direct share menu.

Expected result: Describe here what should happen after you run the steps above (i.e. what would be the correct behaviour)

No contact through signal should be visible in the direct share menu unless you explicitly opt-in for that contact.

Screenshots

Not possible for privacy reasons.

Device info


Device: Google Pixel 2 XL
Android version: 10.0.0
Signal version: current play store

Link to debug log

Not applicable, it's not a crash.

All 2 comments

Hi there, this is working as intended.

So Signal "Private Messenger" is intended to be NOT private at all? Might want to rename it then.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

notthematrix picture notthematrix  路  3Comments

derWalter picture derWalter  路  3Comments

5boro picture 5boro  路  3Comments

j3fffff picture j3fffff  路  3Comments

jult picture jult  路  3Comments