1sealsemantic last-mile verification

Research / Finding

Ignore expireTimerVersion=0 messages

F-SIGNAL-DESKTOP-EXPIRE-001

Public snapshot: 26 Sep 2026. Status, releases and attribution belong to each source below; none is inferred from another record.

Read the evidence · View in research browse

Recorded evidence

—score not recorded
signalapp/Signal-DesktopReported fixsignalapp/Signal-Desktop

Ignore expireTimerVersion=0 messages

Fixed in: v8.5.0

fixed publicly
details
Finding IDs
F-SIGNAL-DESKTOP-EXPIRE-001
Status
fixed publicly
Fixed in
v8.5.0
Reported via
security contact
Note
A zero expiration-timer version could enter conversation timer-state handling instead of being rejected as an invalid version. The public fix chain began with serialization changes on 10 March 2026; commit c863dfa6 of 20 March adds the explicit version === 0 rejection. That check is present in stable v8.5.0, not just the previously recorded 8.10.0 alpha; inspected v8.4.1 still lacks it. This addresses the zero-version state-update path, not a guarantee that conversation participants cannot legitimately change a disappearing-message timer. Source and release inspection do not establish rollout to every desktop installation.

F-SIGNAL-DESKTOP-EXPIRE-001: Input / state handling. Expiration-state handling fails to enforce the intended version cutoff. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-SIGNAL-DESKTOP-EXPIRE-001

Security area (1seal assessment): Integrity. Rejecting zero or stale expiration-timer versions preserves the ordering and integrity of conversation timer state. Reviewed 26 Sep 2026.

Clarify or correct this record privately. The email subject includes the finding ID. For an existing case, continue the agreed private thread. Do not post unpublished vulnerability details in public issues. Research disclosure policy.

How this page groups evidence

This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.