PSA: we have seen the vague viral reports alleging a Signal 0-day vulnerability.

After responsible investigation *we have no evidence that suggests this vulnerability is real* nor has any additional info been shared via our official reporting channels.

We also checked with people across US Government, since the copy-paste report claimed USG as a source. Those we spoke to have no info suggesting this is a valid claim.

We take reports to [email protected] very seriously, and invite those with real info to share it there. 2/

@signalapp
I've seen this make the rounds. Thanks for looking into this. And if anyone is still paranoid about it then disabling link previews should render the alleged threat null.
@signalapp could you please verify your profile? please have a look at https://joinmastodon.org/verification
Verification

Learn how to get verified on Mastodon

@signalapp

Hi,

Could you add a link on signal.org, pointing to your Mastodon profile, with a rel="me" attribute. And then add a link to signal.org on your mastodon profile?
So that your account appears to be certified (to be sure you are not a fake account).

More info here:
https://joinmastodon.org/verification
("here's how" section).

Verification

Learn how to get verified on Mastodon

@John_Livingston @signalapp yes! please please please do this, it makes your account here trustable at a glance.

@John_Livingston @signalapp You've tweeted your handle once, but verifying your account would be waaay better.

https://x.com/signalapp/status/1593678164319997953

Signal on X

Hello, Mastodon - [email protected]

X (formerly Twitter)
@katzentratschen @John_Livingston @signalapp yes, please verify via mastodon’s native mechanism. The tweet would have been useful in the old world where it was leveraging twitter’s own verification, but, alas
@John_Livingston @signalapp I came here to say the same thing. It would be comforting to know that the Mastodon account officially owned by Signal (and not some elaborate impersonation) is dismissing news of a 0-day.

@signalapp Please verify your profile on Mastodon, and maybe mention on it on your website too.

The only official resource that I found linking this account to signal.org is this tweet from the official X/Twitter account and Twitter is not very reliable these days :/

Setting up your profile - Mastodon documentation

Get started with your new account.

@realaravinth Looks verified to me

@photovince Nice 🎉

They weren't verified at that time but this is great!

@Oozenet if that's what happened, then it's taking a slightly older vuln and misunderstanding it as a new vuln, then creating a rumor around it. In which case the rumor is erroneous, yeah, and Signal is correct that there's no "link preview vuln" as claimed.

Hope that helps in understanding.

@signalapp for sure generated by bullshit AI.
@signalapp great that you share it here as well and not only on X 👍... Many of you more security conscious users might have migrated here already (unsubstantiated claim 😉)
@signalapp You really need to verify your account, or move it over to your own server, if you want people to rely on posts like this! It's really easy, just do it!
@signalapp This account isn't listed on the Signal website. Can you provide a proof that it is indeed run by Signal?
@signalapp honestly... xmpp is way better tbh.