chrisrosa's User Avatar

@chrisrosa

in /technology 4 months ago

Subverting code integrity checks to locally backdoor Signal, 1Password, Slack, and more

Subverting code integrity checks to locally backdoor Signal, 1Password, Slack, and more - Featured Image

Subverting code integrity checks to locally backdoor Signal, 1Password, Slack, and more

blog.trailofbits.com - faviconblog.trailofbits.com
TLDR

A vulnerability in Electron applications allows attackers to bypass code integrity checks, enabling local backdoors in apps like Signal, 1Password, and Slack. This exploit involves tampering with V8 heap snapshot files, leading to potential security risks.

Signal, 1Password and Slack have since been patched.

0 Comments