Skip to main content

Vulnerability in Signal messaging app could let hackers track your location

A vulnerability in the secure messaging app Signal could let a bad actor track a user’s location, according to findings from cybersecurity firm Tenable.

Researcher David Wells found that he could track a user’s movements just by calling their Signal number — whether or not the user had his contact information. This could be a big problem for victims of stalking, or for activists and journalists who are trying to avoid government or law enforcement detection to leak information or act in a whistleblower capacity.

Recommended Videos

There are two aspects to the vulnerability, Wells said. One is that if two Signal users have each other as contacts, it’s possible for them to determine each other’s location and IP address by calling, even if the person being called doesn’t answer the phone.

“That feature is not well advertised, and it’s interesting that someone could disclose your location if they’re your contact,” Wells said. “That’s kind of odd.”

It turns out that even if you don’t have a person in your contacts list, they can still roughly determine your rough location just by calling you on Signal. This works even if you don’t pick up or see the call.

“Let’s say I have a burner phone and I just ring your phone, and I do it so quickly that all you see is a missed call from some number,” Wells said. It turns out that’s enough for the caller to see what DNS server your phone automatically connects to. “Usually, it’ll be somewhat near you,” Wells continued. “So I can force that DNS server [near you] to talk to me. By getting that information, I know what DNS server you’re using and I can determine your general location.”

“The core of the issue is that you’re helpless,” Wells said. Simply by calling your phone, which you can’t control, a threat actor could determine your general location.”

“It’s not like clicking on a link [as in phishing],” he said. “Anyone can do this to you.”

Image used with permission by copyright holder

Signal has reportedly already released a patch for the vulnerability via Github, but as of now, it is not yet available through any app stores.

Signal declined to publicly comment when asked about the reported vulnerability, but Wells told Digital Trends that he heard the team was working on an update that would patch the problem.

Signal recently announced it would be rolling out PIN numbers for people to use instead of phone numbers, which may help plug the security hole.

The vulnerability also has limitations. The method isn’t 100% reliable; at one point, Wells called an associate in Pennsylvania as an experiment, and the associated DNS server that responded was 400 miles away in Toronto.

“It’s very coarse,” Wells admitted.

The researcher also wasn’t able to determine a person’s specific address, for example. But when a callee’s phone connected to certain servers, he was able to see clearly what city they were in and track their daily movements.

“We’re not cracking Signal’s encryption or saying don’t use Signal. The sky isn’t falling,” he said. “But for a certain subset of people, this is going to be a problem.”

Maya Shwayder
I'm a multimedia journalist currently based in New England. I previously worked for DW News/Deutsche Welle as an anchor and…
Gemini brings a fantastic PDF superpower to Files by Google app
step of Gemini processing a PDF in Files by Google app.

Google is on a quest to push its Gemini AI chatbot in as many productivity tools as possible. The latest app to get some generative AI lift is the Files by Google app, which now automatically pulls up Gemini analysis when you open a PDF document.

The feature, which was first shared on the r/Android Reddit community, is now live for phones running Android 15. Digital Trends tested this feature on a Pixel 9 running the stable build of Android 15 and the latest version of Google’s file manager app.

Read more
Disney co-chairman reveals why The Acolyte was canceled after one season
Sol wields his lightsaber in The Acolyte episode 8.

Lucasfilm may be in the midst of experiencing a wave of positive attention and success thanks to its latest TV series, Skeleton Crew, but the Jude Law-starring sci-fi show isn't the only Star Wars title that has premiered on Disney+ this year. This past summer, Lucasfilm also debuted The Acolyte, a Sith-centric show set around 100 years before the events of Star Wars: Episode I - The Phantom Menace. Across its eight episodes, the series proved to be critically divisive, and it was only a month after The Acolyte's finale aired that Disney and Lucasfilm announced they would not be bringing the show back for a second season.

In a recent interview with Vulture, Disney Entertainment co-chairman Alan Bergman shed some light on the behind-the-scenes decision to cancel The Acolyte after just one season. "As it relates to Acolyte, we were happy with our performance, but it wasn’t where we needed it to be given the cost structure of that title, quite frankly, to go and make a season 2," Bergman revealed. "That’s the reason why we didn’t do that."

Read more
James Gunn calls Creature Commandos episode the saddest thing he’s ever written
james gunn calls creature commandos weasel episode saddest thing ever written sits at the bottom of a staircase in

Creature Commandos has been splitting its time as of late between the past and present. Its recent episodes have both propelled the show's present-day plot forward and also explored the pasts of characters like The Bride (Indira Varma) and G.I. Robot (Sean Gunn), offering new insights into the tragic events that shaped their identities and led them to their current circumstances. Creature Commandos' fourth and most recent episode, Chasing Squirrels, does the same for Weasel (also Sean Gunn), revealing the horrifying reasons the character was incorrectly blamed for the deaths of multiple schoolchildren.

The episode refrains from explaining what Weasel is or how the character came to be, but it doesn't shy away from the gruesome and tragic details of the "crime" that turned him into a full-blown monster in society's eyes. In an interview with Variety, Creature Commandos creator and DC Studios co-CEO James Gunn reflected on the episode, which is emotionally and narratively dark, even by the Guardians of the Galaxy Vol. 3 filmmaker's standards.

Read more