CVE-2025-24903 - CVE House
Back to Database
Status published High CVE-2025-24903

libsignal-service-rs Doesn't Check Origin of Sync Messages

Vulnerability Description

libsignal-service-rs is a Rust version of the libsignal-service-java library which implements the core functionality to communicate with Signal servers. Prior to commit 82d70f6720e762898f34ae76b0894b0297d9b2f8, any contact may forge a sync message, impersonating another device of the local user. The origin of sync messages is not checked. Patched libsignal-service can be found after commit 82d70f6720e762898f34ae76b0894b0297d9b2f8. The `Metadata` struct contains an additional `was_encrypted` field, which breaks the API, but should be easily resolvable. No known workarounds are available.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-24903

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

whisperfish

View all reports →

Affected Software

libsignal-service-rs
Vulnerable Versions:
< 82d70f6720e762898f34ae76b0894b0297d9b2f8

Timeline

Official Publish: February 13th, 2025
Last Modified: February 13th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N

Weaknesses (CWE)