PSA: we have seen the vague viral reports alleging a Signal 0-day vulnerability.

After responsible investigation *we have no evidence that suggests this vulnerability is real* nor has any additional info been shared via our official reporting channels.

We also checked with people across US Government, since the copy-paste report claimed USG as a source. Those we spoke to have no info suggesting this is a valid claim.

We take reports to [email protected] very seriously, and invite those with real info to share it there. 2/

@signalapp
I've seen this make the rounds. Thanks for looking into this. And if anyone is still paranoid about it then disabling link previews should render the alleged threat null.
@signalapp could you please verify your profile? please have a look at https://joinmastodon.org/verification
Verification

Learn how to get verified on Mastodon