
Signal patches decrypted attachment exfiltration via Intent redirection
GitHub Security Lab reports Signal Android `website` APKs before `v8.4.2` let any installed app exfiltrate decrypted attachments via Intent redirection abusing an unprotected update receiver.
NewsMobile SecurityAndroid
2 min03 Apr 2026
