Signal's Contact Discovery Enclave Compromised via TEE Vulnerabilities
matthew_d_green · x · 2026-08-27
Security researchers at V12 disclosed details on an attack against Signal's Contact Discovery Service (CDSI), achieving full compromise by exploiting vulnerabilities in Intel SGX enclaves.
Vulnerability Details:
- Object-Lifetime Bugs: Two critical vulnerabilities were found, allowing the untrusted host server to breach the enclave boundary.
- Arbitrary Read: The first vulnerability granted the host arbitrary memory read access within the enclave.
- Code Execution: The second vulnerability provided full control over the enclave's register context, enabling code execution inside the enclave.
Attack Impact:
- The attack was demonstrated on real SGX hardware matching Signal's production environment.
- Proof-of-concept code extracted the Noise private key, allowing the host to impersonate the enclave and decrypt user queries.
Status:
- The issues were responsibly disclosed to Signal and have since been fixed.
More from Safety
- Hugging Face Incident Analysis: The Challenge of Overseeing AI Swarms — AdaptiveAgents · 2026-08-27
- Code released: Localizing and intervening on harmful mechanisms in LLMs — boknilev · 2026-08-27
- Above Security CEO: AI agents make insider risk faster and harder to judge — TechNadu · 2026-08-27
- UK Financial Watchdog Warns Britons Against Taking AI Investment Advice — theipaper · 2026-08-27
- EU Collects Feedback on AI Strategy for Culture and Creative Industries — LudovicCreator · 2026-08-27
- Google Won't Penalize All AI Generated Content — dejanseo · 2026-08-27