Failed message verification logs received and computed authentication tags
Fixed in: v0.103.0 library release; downstream application rollout not established
details
- Finding IDs
- F-LIBSIGNAL-MAC-LOG-001
- Status
- fixed publicly
- Fixed in
- v0.103.0 library release; downstream application rollout not established
- Note
- On a failed message MAC comparison, the verifier logged both the received tag and its locally computed counterpart. The 17 September 2026 commit removes that diagnostic output while retaining constant-time comparison and verification failure. The change is present in the v0.103.0 library release. The reported observation requires a failed verification and access to the logs. MAC tags are not encryption keys: removing their log output does not by itself prove prior key recovery, a break of end-to-end encryption, or remote access to logs. Adoption by Signal clients was not independently established in this check. Public-source review does not establish vendor attribution, an assigned severity or a fresh end-to-end retest.
F-LIBSIGNAL-MAC-LOG-001: Secret handling. Authentication-tag values from message verification are unnecessarily exposed through a diagnostic log. Reviewed 26 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-LIBSIGNAL-MAC-LOG-001
Security area (1seal assessment): Confidentiality. Authentication-tag values from message verification are unnecessarily exposed through a diagnostic log. Reviewed 26 Sep 2026.